CVE-2007-3423
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.
cgi-bin/cgi-lib/instantmessage.pl en web-app.org WebAPP anterior a 0.9.9.7 utiliza el campo From de mensaje instantáneo como inicio del nombre de archivo .dat cuando la función (1) imview2 o (2) imview3 lee (a) un IM (mensaje instantáneo) interno, o un mensaje desde un usario (b) invitado o (c) borrado, lo cual tiene impacto y vectores de ataque remotos desconocidos.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-06-26 CVE Reserved
- 2007-06-26 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://osvdb.org/45409 | Vdb Entry | |
http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip | 2008-11-15 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Web-app.org Search vendor "Web-app.org" | Webapp Search vendor "Web-app.org" for product "Webapp" | <= 0.9.9.6 Search vendor "Web-app.org" for product "Webapp" and version " <= 0.9.9.6" | - |
Affected
|