First published: Tue Feb 06 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Messenger | <=8.1.0.209 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0768 is categorized as a moderate severity cross-site scripting vulnerability.
To mitigate CVE-2007-0768, ensure that you upgrade to a patched version of Yahoo Messenger higher than 8.1.0.209.
CVE-2007-0768 enables remote attackers to carry out cross-site scripting attacks via user-assisted methods.
CVE-2007-0768 affects Yahoo Messenger versions 8.1.0.209 and earlier.
CVE-2007-0768 exploits XSS vulnerabilities by allowing attackers to inject arbitrary web scripts through the IMG element's SRC attribute.