Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-1671

Опубликовано: 19 мая 2005
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:5.6:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:5.6.0.1351:*:*:*:*:*:*:*
cpe:2.3:a:yahoo:messenger:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00098
Низкий

2.1 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.

EPSS

Процентиль: 27%
0.00098
Низкий

2.1 Low

CVSS2

Дефекты

NVD-CWE-Other