CVE-2007-1085 describes a Cross-site Scripting (XSS) vulnerability in Google Desktop. This flaw allows remote attackers to bypass security measures and inject arbitrary web script or HTML, potentially leading to full system access. The attack requires exploiting an XSS vulnerability on google.com to extract an internal web server signature, then using it with the "under" parameter in Advanced Search. While the CVSS score is 7.6 (High) due to network access, high attack complexity, and complete confidentiality, integrity, and availability impact, there is no evidence of active exploitation, though exploit code is available on ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:google:desktop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.