Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2007-09-20 21:17
Updated : 2017-09-29 01:29
NVD link : CVE-2007-5017
Mitre link : CVE-2007-5017
CVE.ORG link : CVE-2007-5017
JSON object : View
Products Affected
                yahoo
- messenger
 
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
