Risks
Vulnerabilities
Browse by
ICQ Portal Cross Site Scripting vulnerability
21 September 2001
Bookmark and Share
--[ ICQ Portal multiple Cross Site Scripting vulnerability ]--
Problem discovered: 19/09/2001 by Cabezon Aurélien |
aurelien.cabezon@iSecureLabs.com | http://www.iSecureLabs.com

--[ Overview ]--

The icq portal suffer from multiple Cross Site Scripting Vulnerability. http://www.icq.com

-- [ Description ]--

ICQ web portal may inadvertently include malicious HTML tags or script in a dynamically generated page based on unvalidated input from untrustworthy sources.

This can be a problem when a web server does not adequately ensure that generated pages are properly encoded to prevent unintended execution of scripts, and when input from a form is not validated to prevent malicious HTML from being presented to the user.

This search script http://search.icq.com/dirsearch.adp does not check anymore for malicious HTML or Java Script code.

Exemple 1
http://search.icq.com/dirsearch.adp?query=<h1>Hello</h1><script>alert('hello ');</script>est&wh=is&users=1

Screen Shots:
http://www.isecurelabs.com/advisory/icq1.jpg
http://www.isecurelabs.com/advisory/icq2.jpg

Exemple 2
http://web.icq.com/foo/<script>alert('hello');</script>;

Scree Shots:
http://www.isecurelabs.com/advisory/icq3.jpg
http://www.isecurelabs.com/advisory/icq4.jpg

--[ Fix ]-- ICQ Team has been alerted

--[ Informations about CSS ]--


http://httpd.apache.org/info/css-security/apache_specific.html
http://www.cert.org/advisories/CA-2000-02.html

---
Cabezon Aurélien | aurelien.cabezon@iSecureLabs.com
http://www.iSecureLabs.com | French Security Portal
http://www.isecurelabs.com/advisory/icq-css.html




Spotlight

The evolution of backup and disaster recovery

Posted on 25 July 2014.  |  Amanda Strassle, IT Senior Director of Data Center Service Delivery at Seagate Technology, talks about enterprise backup issues, illustrates how the cloud shaping an IT department's approach to backup and disaster recovery, and more.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Mon, Jul 28th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //