peter bassill · operator
$ cve CVE-2007-1085 JSON

CVE-2007-1085 EXPLOIT

7.6
HIGH · CVSS 2.0 · EPSS 11.1% (pctl 96)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the "under" parameter in Advanced Search with the proper signature.

Scoring

CVSS7.6 (HIGH, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS11.09% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2007-02-23
Last modified2026-06-16

Affected (1)

VendorProduct
googledesktop

Public exploits

SourceTitleDate
exploit-dbGoogle Desktop - Cross-Site Scripting2007-02-21

References

→ the Explorer  ·  watch your stack  ·  NVD