Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ICQ Forced User Addition Vulnerability

If the following data is served to a victim's MSIE browser with the 'application/x-icq' Content-Type, <uin> will be added to their contact list.

[ICQ User]
UIN=<uin>
Email=
NickName=
FirstName=
LastName=

where <uin> is an ICQ UIN

It may be possible to add an arbitrary UIN on some versions of the client using the following link:

http://wwp.icq.com/whitepages/add_me/?uin=<uin>&action=add

where <uin> is the arbitrary UIN to be added to the contact list.







 

Privacy Statement
Copyright 2008, SecurityFocus