Vulnerability Details CVE-2007-0768
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.2%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2007-0768
-
cpe:2.3:a:yahoo:messenger:-
-
cpe:2.3:a:yahoo:messenger:0.99.17-1
-
cpe:2.3:a:yahoo:messenger:1.0
-
cpe:2.3:a:yahoo:messenger:1.0.4
-
cpe:2.3:a:yahoo:messenger:1.0.6
-
cpe:2.3:a:yahoo:messenger:2.0.1.4
-
cpe:2.3:a:yahoo:messenger:3.0
-
cpe:2.3:a:yahoo:messenger:3.0.1
-
cpe:2.3:a:yahoo:messenger:3.5
-
cpe:2.3:a:yahoo:messenger:4.0
-
cpe:2.3:a:yahoo:messenger:4.1
-
cpe:2.3:a:yahoo:messenger:5.0
-
cpe:2.3:a:yahoo:messenger:5.0.1046
-
cpe:2.3:a:yahoo:messenger:5.0.1065
-
cpe:2.3:a:yahoo:messenger:5.0.1232
-
cpe:2.3:a:yahoo:messenger:5.5
-
cpe:2.3:a:yahoo:messenger:5.5.1249
-
cpe:2.3:a:yahoo:messenger:5.6
-
cpe:2.3:a:yahoo:messenger:5.6.0.1347
-
cpe:2.3:a:yahoo:messenger:5.6.0.1351
-
cpe:2.3:a:yahoo:messenger:5.6.0.1355
-
cpe:2.3:a:yahoo:messenger:5.6.0.1356
-
cpe:2.3:a:yahoo:messenger:5.6.0.1358
-
cpe:2.3:a:yahoo:messenger:6.0
-
cpe:2.3:a:yahoo:messenger:6.0.0.1643
-
cpe:2.3:a:yahoo:messenger:6.0.0.1750
-
cpe:2.3:a:yahoo:messenger:6.0.0.1921
-
cpe:2.3:a:yahoo:messenger:6.1
-
cpe:2.3:a:yahoo:messenger:7.0
-
cpe:2.3:a:yahoo:messenger:7.0.0.426
-
cpe:2.3:a:yahoo:messenger:7.0.0.437
-
cpe:2.3:a:yahoo:messenger:7.0.438
-
cpe:2.3:a:yahoo:messenger:7.5
-
cpe:2.3:a:yahoo:messenger:7.5.0.814
-
cpe:2.3:a:yahoo:messenger:8.0
-
cpe:2.3:a:yahoo:messenger:8.0.0.505
-
cpe:2.3:a:yahoo:messenger:8.0.0.508
-
cpe:2.3:a:yahoo:messenger:8.0.0.701
-
cpe:2.3:a:yahoo:messenger:8.0.0.716
-
cpe:2.3:a:yahoo:messenger:8.0.0.863
-
cpe:2.3:a:yahoo:messenger:8.0.1
-
cpe:2.3:a:yahoo:messenger:8.0_2005.1.1.4
-
cpe:2.3:a:yahoo:messenger:8.1
-
cpe:2.3:a:yahoo:messenger:8.1.0.195
-
cpe:2.3:a:yahoo:messenger:8.1.0.209