First published: Thu May 11 2006(Updated: )
Cross-Application Scripting (XAS) vulnerability in ICQ Client 5.04 build 2321 and earlier allows remote attackers to inject arbitrary web script from one application into another via a banner, which is processed in the My Computer zone using the Internet Explorer COM object.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CenterICQ | =5.04_build2321 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2303 is considered to be a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2006-2303, upgrade to a newer version of the ICQ Client that addresses this vulnerability.
CVE-2006-2303 specifically affects ICQ Client versions 5.04 build 2321 and earlier.
CVE-2006-2303 is classified as a Cross-Application Scripting (XAS) vulnerability.
Yes, CVE-2006-2303 can be exploited remotely allowing attackers to inject arbitrary web scripts from one application to another.