Vulnerability Description
ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mirabilis | Icq | 2000.0a |
References
- http://marc.info/?l=bugtraq&m=99851887024728&w=2
- http://www.iss.net/security_center/static/7028.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/3226
- http://marc.info/?l=bugtraq&m=99851887024728&w=2
- http://www.iss.net/security_center/static/7028.phpPatchVendor Advisory
- http://www.securityfocus.com/bid/3226
FAQ
What is CVE-2001-1305?
CVE-2001-1305 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is process...
How severe is CVE-2001-1305?
CVE-2001-1305 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1305?
Check the references section above for vendor advisories and patch information. Affected products include: Mirabilis Icq.