Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yahoo! Messenger可插入脚本漏洞
Vulnerability Description
Yahoo! Messenger(雅虎通)是美国雅虎(Yahoo!)公司推出的一套即时聊天工具。 Yahoo! Messenger中的"ymsgr:addview?"功能存在漏洞,可导致远程攻击者进行跨站脚本执行攻击。 Yahoo! Messenger在安装时会配置'ymsgr:' URI句柄,在Win98系统下,注册表中为HKEY_LOCAL_MACHINE\Software\CLASSES\ymsgr\shell\open\command,默认值为"<Hard-drive:\Directories\>
CVSS Information
N/A
Vulnerability Type
N/A