CVE-2007-2354: High severity Progress Webspeed Messenger vulnerability
Published Apr 30, 2007
·Updated
Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.
Affected Software
1 affected component
Progress Webspeed Messenger
Event History
Apr 30, 2007
CVE Published
10:19 PM
May 1, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2354?
The severity of CVE-2007-2354 is classified as medium due to its potential to expose sensitive information.
2
How do I fix CVE-2007-2354?
To fix CVE-2007-2354, update Progress Webspeed Messenger to the latest version that addresses this vulnerability.
3
What information can be exposed through CVE-2007-2354?
CVE-2007-2354 can expose sensitive information including the operating system and product details.
4
Which versions of Progress Webspeed Messenger are affected by CVE-2007-2354?
CVE-2007-2354 affects all versions of Progress Webspeed Messenger prior to the security update.
5
Can CVE-2007-2354 be exploited remotely?
Yes, CVE-2007-2354 can be exploited remotely by attackers targeting the WService parameter.