ICQ Banner Ad Cross-Application Scripting Vulnerability

ICQ is prone to a cross-application scripting vulnerability. This issue is a result of the application accessing content in a different and presumably higher security context than the original content.

An attacker can exploit this issue to have arbitrary attacker-supplied HTML or JavaScript executed on a victim user's computer in the 'My Computer' security zone.


 

Privacy Statement
Copyright 2010, SecurityFocus