|
Brought to you by:
Suppliers of:
|
|
|
| |
| Tlen.pl is the instant messenger application. A vulnerability in Tlen.pl's message parsing allows remote execution of arbitrary script. |
| |
Credit:
The information has been provided by Jaroslaw Sajko.
|
| |
Vulnerable Systems:
* Tlen.pl Version 5.23.4.1 and prior
Immune Systems:
* Tlen.pl Version 5.23.4.2
A parsing error allow a malicious user to send a string which has an URL inside. If the can include JavaScript code for example, the script code will execute when the window with the message pops up.
Example:
Sending the following link to any recipient: www.tlen.pl"style=background-image:url(javascript:alert(%22You%20are%20owned!%22));.pl
Will cause him to open a JavaScript message box in the client's machine when he/she open the message window.
Vendor Status:
The vendor has released version 5.23.4.2 that addresses this issue.
|
|
|
|
|