← Back

CVE-2007-3423

nvd nist
Published: Jun 26, 2007Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.

Affected (1)

Products: Web App.org: Webapp
1 product
Webapp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.9.6

References (6)

Timeline

No history available yet.