ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
BID:19900
CVE-2006-4660 | CVE-2006-4661 |Info
ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
| Bugtraq ID: | 19900 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2006 12:00AM |
| Updated: | Sep 08 2006 05:22PM |
| Credit: | Lucas Lavarello, Sebastian Cufre, Ezequiel Gutesman, Javier Garcia Di Palma and Luciana Tabo from Core Security Technologies are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Icq ICQ Toolbar 1.3 Icq ICQ Toolbar 1.2 |
| Not Vulnerable: | |
Discussion
ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
ICQ Toolbar for Internet Explorer is prone to multiple vulnerabilities.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of an unsuspecting victim and control configurations settings for the affected application. This may allow the attacker to control how the site is rendered in the browser, to steal cookie-based authentication credentials, or to aid in further attacks.
These issues affect ICQ Toolbar version 1.3 for Internet Explorer; other versions may also be vulnerable.
ICQ Toolbar for Internet Explorer is prone to multiple vulnerabilities.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of an unsuspecting victim and control configurations settings for the affected application. This may allow the attacker to control how the site is rendered in the browser, to steal cookie-based authentication credentials, or to aid in further attacks.
These issues affect ICQ Toolbar version 1.3 for Internet Explorer; other versions may also be vulnerable.
Exploit / POC
ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
Attackers can exploit these issues by constructing a malicious RSS feed or web page.
Attackers can exploit these issues by constructing a malicious RSS feed or web page.
Solution / Fix
ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
ICQ Toolbar HTML Injection and Unauthorized Access Vulnerabilities
References:
References:
- ICQ Homepage (ICQ Inc.)
- Multiple vulnerabilities in ICQ Toolbar 1.3 for Internet Explorer (Core Security)
- CORE-2006-0322: Multiple vulnerabilities in ICQ Toolbar 1.3 for Internet Explore (CORE Security Technologies Advisories)