vendor:
ICQ Pro 2003a
by:
Caua Moura Prado (aka ca1)
7.5
CVSS
HIGH
Bypass vulnerability
CWE
Product Name: ICQ Pro 2003a
Affected Version From: ICQ Pro 2003a Build #3800
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2003
ca1-icq.asm – ICQ Password Bypass exploit
This exploit allows you to login to ICQ server using any account registered locally, no matter the 'save password' option is checked or not. High-level security is also bypassed. All you have to do is run the exploit and set the status property using your mouse when the flower is yellow. If you accidentally set the status to offline then you will need to restart ICQ and run the exploit again.
Mitigation:
Upgrade to a non-vulnerable version of ICQ.