[19226] in bugtraq
Re: Security hole in kicq
daemon@ATHENA.MIT.EDU (Wolter Kamphuis)
Thu Feb 15 15:09:44 2001
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id: <Pine.LNX.4.21.0102142153470.3588-100000@wit393303.student.utwente.nl>
Date: Wed, 14 Feb 2001 21:56:10 +0100
Reply-To: Wolter Kamphuis <w.r.kamphuis@STUDENT.UTWENTE.NL>
From: Wolter Kamphuis <w.r.kamphuis@STUDENT.UTWENTE.NL>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <20010214144610.A436@tentacle.franken.de>
> I tried with version 1.0.0, it is vulnerable for sure.
> Other versions (such as 2.0.0b1) seem to be vulerable as well,
> though i did not compile them to try.
>
one little try shows that licq (http://licq.org) is vulerable too however the
complete url will be visible to the user.
greets,
Wolter