Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Messenger |
Yahoo |
5.0 (including) |
5.0 (including) |
References