CVE-2007-3423
published 2007-06-26CVE-2007-3423: cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when…
PriorityP425high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.13%
62.3th percentile
cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| web-app.org | webapp | <= 0.9.9.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/45409http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458http://www.web-app.org/downloads/WebAPPv0.9.9.7.ziphttp://osvdb.org/45409http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip
2007-06-26
Published