Yahoo! Messenger IMVironment...

- AV AC AU C I A
发布: 2003-12-05
修订: 2025-04-13

Yahoo! Messenger is prone to a cross-site scripting vulnerability via IMVironment error dialogs. This may occur when a 'ymsgr' URI specifies an invalid IMVironment that includes hostile HTML and script code. This could permit various attacks since the attacker may execute hostile script code in the context of the client. Consequences include exposure of Yahoo messenger IDs and encoded credentials. It should also be noted that this issue could potentially be exploited to corrupt IMVironment data, causing the client to not function properly.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息