[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-Disclosure] Tlen.pl, remote script execution
- To: bugtraq@xxxxxxxxxxxxxxxxx, <full-disclosure@xxxxxxxxxxxxxxxx>
- Subject: [Full-Disclosure] Tlen.pl, remote script execution
- From: Jaroslaw Sajko <sloik@xxxxxxxxxxxxx>
- Date: Mon, 20 Dec 2004 12:31:32 +0100 (CET)
Product: Tlen.pl (<= 5.23.4.1)
Vendor: o2.pl Sp. z o.o. (http://www.tlen.pl/)
Impact: Remote script execution
Severity: High
Authors: Blazej Miga <bla@xxxxxxxxxxxxx>,
Jaroslaw Sajko <sloik@xxxxxxxxxxxxx>
Date: 20/12/04
[ISSUE]
Tlen.pl is the instant messenger application used by more than 700 000
users.
There is a vulnerability in message parsing which allows remote execution
of arbitrary script.
[DETAILS]
There is a parsing error. We can send a malicious string which has an url
inside. This url can be a javascript code for example. Code will execute
when the window with the message pops up.
[POF]
Send such a string to any receipent:
www.tlen.pl"style=background-image:url(javascript:alert(%22You%20are%20owned!%22));.pl
[SOLUTION]
Please upgrade to the newest version (5.23.4.2)
Copyright Poznan Supercomputing and Networking Center
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html