Vulnerability Details CVE-2003-0237
The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2003-0237
-
cpe:2.3:a:mirabilis:icq:2000.0a
-
cpe:2.3:a:mirabilis:icq:2000.0b_build3278
-
cpe:2.3:a:mirabilis:icq:2001a
-
cpe:2.3:a:mirabilis:icq:2001b_build3636
-
cpe:2.3:a:mirabilis:icq:2001b_build3638
-
cpe:2.3:a:mirabilis:icq:2001b_build3659
-
cpe:2.3:a:mirabilis:icq:2002a_build3722
-
cpe:2.3:a:mirabilis:icq:2002a_build3727
-
cpe:2.3:a:mirabilis:icq:2003a_build3777
-
cpe:2.3:a:mirabilis:icq:2003a_build3799
-
cpe:2.3:a:mirabilis:icq:2003a_build3800
-
cpe:2.3:a:mirabilis:icq:99a_2.15build1701
-
cpe:2.3:a:mirabilis:icq:99a_2.21build1800