Skype HTML Injection and Caller Spoofing
Publicado: 08 Jul 2013, 21:21
The latest Windows Skype client as of 7/7/2013 is vulnerable to Restricted HTML Injection and To/From Caller Spoofing. It is possible to inject certain HTML tags in the search bar. It is possible to swap who is calling who locally by adding the token=1 argument. It is possible to bypass the application launch and call confirmation dialog windows if skype link is launched from Injection.
TEST DEMO :
[Enlace externo eliminado para invitados]
el baul esta lleno de 0days me pregunto si lo liberare algun dia
TEST DEMO :
[Enlace externo eliminado para invitados]
el baul esta lleno de 0days me pregunto si lo liberare algun dia