Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ICQ Forced User Addition Vulnerability

ICQ is an instant messaging application from Mirabilis.

A webserver can force the addition of arbitrary ICQ UINs to a target user's ICQ contact list if they are running ICQ and browsing with Microsoft Internet Explorer.

This is due to the way Explorer and ICQ handle data returned from a webserver with a 'application/x-icq' Content-Type. In more recent versions of the ICQ client, the user is prompted to add a user to the contact list.







 

Privacy Statement
Copyright 2008, SecurityFocus