First published: Mon Apr 30 2007(Updated: )
Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Webspeed Messenger |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-2354 is classified as medium due to its potential to expose sensitive information.
To fix CVE-2007-2354, update Progress Webspeed Messenger to the latest version that addresses this vulnerability.
CVE-2007-2354 can expose sensitive information including the operating system and product details.
CVE-2007-2354 affects all versions of Progress Webspeed Messenger prior to the security update.
Yes, CVE-2007-2354 can be exploited remotely by attackers targeting the WService parameter.