Popular VoIP software Skype contains a vulnerability that could allow an attacker toget access to your account. Levent Kayan, who found the vulnerability in his reviewindicated that in some cases it is possible to access a user’s system.
An attacker can inject JavaScript in the mobile phone or the field “about yourself.”These fields are not filtered, and when someone from the contact list in Skype comes to the attacker’s injected code automatically.
XSS vulnerability found in versions of Skype 5.3.0.120 and earlier Windows and Mac,and not always reproduced. Linux version is not affected. At the moment, fix did not work.
Skype developers have confirmed the vulnerability and vowed to release a patchwithin the next week. They also explained why the vulnerability does not always play: it is necessary that the attacker was on the list of popular contacts. They alsoclassified the issue as not very significant, because alleged attacker can only display a message or redirect to another page.
No Replies to "XSS vulnerability in Skype"