Yahoo! Messenger ymsgr URI Arbitrary Script Execution

medium Nessus Network Monitor Plugin ID 1263

Synopsis

The remote host passes information across the network in an insecure manner

Description

The remote host is running a version of Yahoo Instant Messenger that does not encrypt user passwords when authenticating a user during login. Anyone monitoring the local segment can thus extract the passwords of the user running the client.

Solution

Upgrade to the latest version of Yahoo Instant Messenger.

Plugin Details

Severity: Medium

ID: 1263

Published: 8/20/2004

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 5.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 6.3

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:yahoo:messenger

Reference Information

CVE: CVE-2002-0322

BID: 4173