WHID 2006-23: ICQ search vulnerable to XSS
ICQ.com search script (search_result.php) is vulnerable to cross-site scripting attacks. This problem is due to a failure
in the application to properly sanitize user input, the input can be passed to the vulnerable script in 2 variables
(gender and home_country_code).
Additional information:
- ICQ Cross Site Scripting [Simo Ben Youssef, Jan 10 2006]
Attack Method:
Incident Outcome: