Vulnerability Development mailing list archives

Re: Yahoo Messenger 7.0.0.438 Crash Tested


From: Ivancool2003 () yahoo com ar
Date: 18 Jun 2006 00:40:17 -0000

Remote crash proof of concept:
1. Open messenger and log it.
2. Open a yahoo chat third party like yahelite through Ymsgr protocol and log it with another account.
3. Send a Pm to the messenger account with this string: "s: msg :---------------------------------------------iframe 
onload=$InlineAction()>:)" (without quotes)
4. The remote user will crash closing down her messenger.
Note: "msg :" this space must be created with alt+0160.


Current thread: