|
ICQ Forced User Addition Vulnerability
ICQ is an instant messaging application from Mirabilis. A webserver can force the addition of arbitrary ICQ UINs to a target user's ICQ contact list if they are running ICQ and browsing with Microsoft Internet Explorer. This is due to the way Explorer and ICQ handle data returned from a webserver with a 'application/x-icq' Content-Type. In more recent versions of the ICQ client, the user is prompted to add a user to the contact list. |
|
|
Privacy Statement |