First published: Fri Aug 17 2001(Updated: )
ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CenterICQ | =2000.0a | |
CenterICQ | =2000.0b_build3278 | |
CenterICQ | =2001a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1305 is considered a medium-severity vulnerability due to its impact on user privacy and security.
To mitigate CVE-2001-1305, users should avoid using the affected versions of ICQ and consider updating to a more secure version.
CVE-2001-1305 targets versions of ICQ 2001a Alpha and earlier by allowing attackers to manipulate the user's contact list.
Users of ICQ versions 2000.0a, 2000.0b_build3278, and 2001a are affected by CVE-2001-1305.
The attack vector for CVE-2001-1305 is through a specially crafted web page that uses the application/x-icq MIME type.