CVE-2008-0454
Microsoft Internet Explorer < 3.6.0.244 - XSS
Title source: ruleDescription
Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."
References (13)
Scores
EPSS
0.4365
EPSS Percentile
97.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (4)
microsoft/internet_explorer
skype_technologies/skype
< 3.6.0.244
skype_technologies/skype
skype_technologies/skype
Timeline
Published
Jan 25, 2008
Tracked Since
Feb 18, 2026