CVE-2006-4975: Low severity yahoo messenger vulnerability
Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4975?
CVE-2006-4975 is classified as a moderate severity vulnerability due to the user-assisted nature of the exploitation.
How do I fix CVE-2006-4975?
To mitigate CVE-2006-4975, users should avoid saving messages that contain JavaScript and consider updating to a newer version of Yahoo! Messenger.
What types of attacks are possible with CVE-2006-4975?
CVE-2006-4975 allows user-assisted remote attackers to inject arbitrary web script or HTML into the application.
Which versions of Yahoo Messenger are affected by CVE-2006-4975?
CVE-2006-4975 affects all versions of Yahoo! Messenger that support WAP functionality.
Is CVE-2006-4975 exploitable without user interaction?
CVE-2006-4975 requires user interaction for exploitation, as it depends on the victim saving messages containing malicious scripts.