|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
This Entry needs help! It is only 35% Complete. Click the edit link above to add more information.
Contributing is fast and easy, and benefits the entire security community.
|
|
Description |
(Description Provided by CVE) : cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.
|
|
Classification |
Solution:
Upgrade
Disclosure:
Vendor Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 0.9.9.7 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
Unknown or Incomplete
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|