CVE-2018-10000
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
- Affected products
- Video Downloader Professional Extension
- Videodownloaderultimate Video Downloader
- < 2018-04-05
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2018-04-11
CVE-2018-10000 at NVD
9 known exploits for CVE-2018-10000
Proof-of-concept code and exploit modules indexed by Sploitus
CMS Made Simple 2.2.5 Authenticated Remote Command Execution Exploit
Nanopool Claymore Dual Miner APIs Remote Code Execution Exploit
CMSMadeSimple 2.2.5 - Remote Code Execution Exploit
glibc - realpath() Privilege Escalation Exploit
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution Vulnerability
Exodus Wallet (ElectronJS Framework) - Remote Code Execution Exploit
InfoZip UnZip 6.00 / 6.1c22 Buffer Overflow Vulnerability
Exodus Wallet (ElectronJS Framework) - Remote Code Execution Exploit
glibc - getcwd() Local Privilege Escalation Exploit