Vulnerabilities > CVE-2000-0552 - Incomplete Cleanup vulnerability in ICQ 2000A
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
Common Weakness Enumeration (CWE)
Exploit-Db
description | Mirabilis ICQ 2000.0 A Mailclient Temporary Link Vulnerability. CVE-2000-0552. Local exploit for windows platform |
id | EDB-ID:19993 |
last seen | 2016-02-02 |
modified | 2000-06-06 |
published | 2000-06-06 |
reporter | Gert Fokkema |
source | https://www.exploit-db.com/download/19993/ |
title | Mirabilis ICQ 2000.0 A Mailclient Temporary Link Vulnerability |
Nessus
NASL family | Windows |
NASL id | ICQ_VULNS.NASL |
description | There are multiple flaws in versions of ICQ before 2003b, including some that may allow an attacker to execute arbitrary code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11572 |
published | 2003-05-05 |
reporter | This script is Copyright (C) 2003-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/11572 |
title | ICQ < 2003b Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html
- http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html
- http://www.securityfocus.com/bid/1307
- http://www.securityfocus.com/bid/1307
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4607
- https://exchange.xforce.ibmcloud.com/vulnerabilities/4607