Vulnerability CVE-2013-6237


Published: 2013-12-10

Description:
The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
ISL Light Desktop 3.5.4 Information Disclosure
J. Francisco Bol...
04.12.2013

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:M/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Islonline -> Isl desktop plugin 
Islonline -> Isl light 

 References:
http://www.islonline.com/help/isl-releases-info/any/manual/?2013-11-29-rel-info-isl-light-desktop-plugin-1-4-7-win.htm
http://xforce.iss.net/xforce/xfdb/89399
http://www.securityfocus.com/bid/64050
http://seclists.org/fulldisclosure/2013/Dec/14
http://packetstormsecurity.com/files/124274/ISL-Light-Desktop-3.5.4-Information-Disclosure.html
http://osvdb.org/100512

Copyright 2024, cxsecurity.com

 

Back to Top