5
CVSSv2

CVE-2007-5017

Published: 20/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote malicious users to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

yahoo messenger 8.1.0.421

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol"><body bgcolor="#E0E0E0">----------------------------------------------------------------------------- <b>Yahoo! Messenger 810421 CYFT Object (ft60dll) Arbitrary File Download</b> url: downloadyahoocom/dl/msgr8/us/ ...