AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icq_toolbar | Icq_inc | 1.3_for_internet_explorer (including) | 1.3_for_internet_explorer (including) |