+-----------------------------------------------------------------------------+ | noptrix.net - Public Security Advisory | +-----------------------------------------------------------------------------+ Date: ----- 08/02/2011 Vendor: ------- Adium - http://www.adium.im/ Affected Software: ------------------ Software: Adium Version: <= 1.4.2 Affected Platforms: ------------------- Mac OS X (10.6.8, 10.6.7, maybe also other...) Vulnerability Class: -------------------- HTML/Javascript-Injection / Cross-Site Scripting Description: ------------ Adium suffers from a persistent HTML/Javascript injection / Cross-Site Scripting vulnerability due to a lack of input validation and output sanitization of filenames. Proof of Concept: ----------------- The following HTML/Javascript payload can be used as a filename to trigger the described vulnerability: --- SNIP --- sh3ll$ echo "123" > \"\>\\0x90trix\ pwns\ -\ XSS\ POWER\ \