Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-0454 Details

Description

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0337.html CVE
http://archives.neohapsis.com/archives/fulldisclosure/2008-01/0363.html CVE
http://aviv.raffon.net/2008/01/17/SkypeCrosszoneScriptingVulnerability.aspx CVE
https://exchange.xforce.ibmcloud.com/vulnerabilities/39754 CVE
http://share.skype.com/sites/security/2008/01/skype_cross_zone_scripting_vul.html CVE

see all 26 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]

Affected Products

ProductVersions
microsoft windows
All versions

CPE

  • cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
microsoft internet explorer
All versions

CPE

  • cpe:2.3:a:microsoft:internet_explorer:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
skype technologies skype
<= 3.6.0.244
3.5
3.6

CPE

  • cpe:2.3:a:skype_technologies:skype:*:*:*:*:*:*:*:*
  • cpe:2.3:a:skype_technologies:skype:3.5:*:*:*:*:*:*:*
  • cpe:2.3:a:skype_technologies:skype:3.6:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-0454
NVD Published Date:
Jan 25, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-0454 Details - Not Deferred