PT-2006-5445 · Aol · Aol Icq Toolbar
Ezequiel Gutesman
+4
·
Published
2006-09-09
·
Updated
2018-10-17
·
CVE-2006-4660
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AOL ICQ Toolbar version 1.3
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module. These vulnerabilities allow remote attackers to execute arbitrary web script or HTML within the Feeds interface context. The attack can be carried out via the
title and description elements within an item element in an RSS feed.Recommendations
For AOL ICQ Toolbar version 1.3, as a temporary workaround, consider disabling the RSS Feed module until a patch is available. Restrict access to the Feeds interface to minimize the risk of exploitation. Avoid using the
title and description elements within RSS feeds in the affected module until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aol Icq Toolbar