Skype Multiple Fields Multiple HTML Injection Vulnerabilities
BID:49194
Info
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 49194 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2011 12:00AM |
| Updated: | Aug 17 2011 12:00AM |
| Credit: | Levent 'noptrix' Kayan |
| Vulnerable: |
Skype Technologies Skype 4.2 169 Skype Technologies Skype 4.2 155 Skype Technologies Skype 4.2 152 Skype Technologies Skype 4.1 .179 Skype Technologies Skype 4.1 .179 Skype Technologies Skype 4.1 .166 Skype Technologies Skype 4.1 .141 Skype Technologies Skype 4.1 .136 Skype Technologies Skype 4.1 .130 Skype Technologies Skype 4.0 .227 Skype Technologies Skype 4.0 .226 Skype Technologies Skype 4.0 .224 Skype Technologies Skype 4.0 .216 Skype Technologies Skype 4.0 .215 Skype Technologies Skype 4.0 .206 Skype Technologies Skype 5.5.0.113 Skype Technologies Skype 5.5 Skype Technologies Skype 5.4 Skype Technologies Skype 5.3.0.120 Skype Technologies Skype 5.3 Skype Technologies Skype 5.0.0.105 Skype Technologies Skype 4.2.0.166 Skype Technologies Skype 4.2.0.163 Skype Technologies Skype 4.2.0.158 |
| Not Vulnerable: | |
Discussion
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
Skype is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Skype versions 5.5.0.113 and prior are vulnerable.
Skype is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Skype versions 5.5.0.113 and prior are vulnerable.
Exploit / POC
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
Attackers can use the application to exploit these issues.
The following sample inputs are available:
Home Phone Number:
<b>INJECTION HERE</b>
Office Phone Number:
<center><i>INJECTION HERE</i></center>
Mobile Phone Number:
<a href="#">INJECTION HERE</a>
Attackers can use the application to exploit these issues.
The following sample inputs are available:
Home Phone Number:
<b>INJECTION HERE</b>
Office Phone Number:
<center><i>INJECTION HERE</i></center>
Mobile Phone Number:
<a href="#">INJECTION HERE</a>
Solution / Fix
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Skype Multiple Fields Multiple HTML Injection Vulnerabilities
References:
References:
- Skype (<= 5.5.0.113, Windows) html/js code injection vulnerability (noptrix)
- Skype Homepage (Skype Technologies)