101482vdb entry
http://www.securityfocus.com/bid/101482 CVE-2017-5124
MEDIUM
Webkit (Chome < 61) - 'MHTML' Universal Cross-site Scripting
Record summary
CVE-2017-5124 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Google Chrome prior to 62.0.3202.62 | CVE List | Google Chrome prior to 62.0.3202.62 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWebkit (Chome < 61) - 'MHTML' Universal Cross-site ScriptingExploitDB exploitby Anton LopanitsynNot analyzed1 file
Repository PoCs
GitHubBo0oM/CVE-2017-5124Repository PoCby Bo0oMStars: 160Not analyzed3 files
References
10RHSA-2017:2997Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2997 chromereleases.googleblog.com
https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop.html chromium.googlesource.com
https://chromium.googlesource.com/chromium/src/+/4558c2885e618557a674660aff57404d25537070 crbug.com
https://crbug.com/762930 github.com
https://github.com/Bo0oM/CVE-2017-5124 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-5124 GLSA-201710-24Vendor advisory
https://security.gentoo.org/glsa/201710-24 DSA-4020Vendor advisory
https://www.debian.org/security/2017/dsa-4020 reddit.com
https://www.reddit.com/r/netsec/comments/7cus2h/chrome_61_uxss_exploit_cve20175124