Mirabilis ICQ Password Bypass Weakness
BID:8111
Info
Mirabilis ICQ Password Bypass Weakness
| Bugtraq ID: | 8111 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 05 2003 12:00AM |
| Updated: | Jul 05 2003 12:00AM |
| Credit: | Discovery of this issue credited to "Caua" Moura Prado <[email protected]>. |
| Vulnerable: |
Mirabilis ICQ 2003 a Build#3800 Mirabilis ICQ 2003 a Build#3799 Mirabilis ICQ 2003 a Build#3777 |
| Not Vulnerable: | |
Discussion
Mirabilis ICQ Password Bypass Weakness
An issue has been reported for ICQ that may result in an attacker obtaining access to another ICQ user's account.
Through the use of a certain API, it is possible to access the victim user's ICQ account regardless of existing security measures.
An issue has been reported for ICQ that may result in an attacker obtaining access to another ICQ user's account.
Through the use of a certain API, it is possible to access the victim user's ICQ account regardless of existing security measures.
Exploit / POC
Mirabilis ICQ Password Bypass Weakness
The following proof of concept was provided:
The following proof of concept was provided:
References
Mirabilis ICQ Password Bypass Weakness
References:
References:
- ICQ Homepage (Mirabilis)
- ICQ 2003a Password Bypass ("Caua" Moura Prado
)