Lucene search

K
cvelistMitreCVELIST:CVE-2007-0768
HistoryFeb 06, 2007 - 2:00 a.m.

CVE-2007-0768

2007-02-0602:00:00
mitre
www.cve.org
7

AI Score

5.8

Confidence

High

EPSS

0.005

Percentile

76.1%

Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.

AI Score

5.8

Confidence

High

EPSS

0.005

Percentile

76.1%

Related for CVELIST:CVE-2007-0768