vendor:
Yahoo! Messenger
by:
shinnai
N/A
CVSS
N/A
Arbitrary File Download
CWE
Product Name: Yahoo! Messenger
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2
2007
Yahoo! Messenger 8.1.0.421 CYFT Object (ft60.dll) Arbitrary File Download
This exploit allows an attacker to download an arbitrary file on the user's pc using the 'GetFile()' method in the CYFT Object (ft60.dll) in Yahoo! Messenger 8.1.0.421. Remote execution depends on Internet Explorer settings, while local execution works very well.