Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
BID:9158
Info
Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
| Bugtraq ID: | 9158 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2003 12:00AM |
| Updated: | Dec 05 2003 12:00AM |
| Credit: | Discovery is credited to Chet Simpson <[email protected]>. |
| Vulnerable: |
Yahoo! Messenger 5.6 .0.1355 Yahoo! Messenger 5.6 .0.1347 Yahoo! Messenger 5.6 Yahoo! Messenger 5.5 .1249 Yahoo! Messenger 5.5 |
| Not Vulnerable: | |
Discussion
Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
Yahoo! Messenger is prone to a cross-site scripting vulnerability via IMVironment error dialogs. This may occur when a 'ymsgr' URI specifies an invalid IMVironment that includes hostile HTML and script code. This could permit various attacks since the attacker may execute hostile script code in the context of the client. Consequences include exposure of Yahoo messenger IDs and encoded credentials.
It should also be noted that this issue could potentially be exploited to corrupt IMVironment data, causing the client to not function properly.
Yahoo! Messenger is prone to a cross-site scripting vulnerability via IMVironment error dialogs. This may occur when a 'ymsgr' URI specifies an invalid IMVironment that includes hostile HTML and script code. This could permit various attacks since the attacker may execute hostile script code in the context of the client. Consequences include exposure of Yahoo messenger IDs and encoded credentials.
It should also be noted that this issue could potentially be exploited to corrupt IMVironment data, causing the client to not function properly.
Exploit / POC
Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Yahoo! Messenger IMVironment Cross-Site Scripting Vulnerability
References:
References:
- Yahoo! Messenger Homepage (Yahoo!)
- Yahoo Messenger Flaw allows injection of JavaScript into IM Windows (Chet Simpson
)