CVE-2008-0454

Microsoft Internet Explorer < 3.6.0.244 - XSS

Title source: rule

Description

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

Scores

EPSS 0.4365
EPSS Percentile 97.5%

Classification

CWE
CWE-79
Status draft

Affected Products (4)

microsoft/internet_explorer
skype_technologies/skype < 3.6.0.244
skype_technologies/skype
skype_technologies/skype

Timeline

Published Jan 25, 2008
Tracked Since Feb 18, 2026