CVE-2007-0768: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0768?
CVE-2007-0768 is categorized as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2007-0768?
To mitigate CVE-2007-0768, ensure that you upgrade to a patched version of Yahoo Messenger higher than 8.1.0.209.
What type of attack does CVE-2007-0768 enable?
CVE-2007-0768 enables remote attackers to carry out cross-site scripting attacks via user-assisted methods.
What versions of Yahoo Messenger are affected by CVE-2007-0768?
CVE-2007-0768 affects Yahoo Messenger versions 8.1.0.209 and earlier.
How does CVE-2007-0768 exploit XSS vulnerabilities?
CVE-2007-0768 exploits XSS vulnerabilities by allowing attackers to inject arbitrary web scripts through the IMG element's SRC attribute.