VYPR
Unrated severityNVD Advisory· Published May 19, 2005· Updated Apr 16, 2026

CVE-2005-1671

CVE-2005-1671

Description

The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users.

Affected products

4
  • Yahoo/Messenger4 versions
    cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:yahoo:messenger:5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:yahoo:messenger:5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:yahoo:messenger:5.6.0.1351:*:*:*:*:*:*:*
    • cpe:2.3:a:yahoo:messenger:6.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.