6.8
CVSSv2

CVE-2007-0059

Published: 05/01/2007 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted malicious users to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 3.0

apple quicktime

Exploits

#!/usr/bin/ruby # # (c) 2006 LMH <lmh [at] info-pullcom> # Original scripting and POC by Aviv Raff (avivraffonnet) # # Description: # Exploit for MOAB-03-01-2007 If argument 'serve' is passed, it uses port 21 for running the # fake FTP server (required) HTTP server port can be modified but it's # not recommended Adjust as ...