Description
|
|
Sony has discovered a vulnerability in Nimbuzz, which can be exploited by malicious users to conduct script insertion attacks.
Input passed to the chat is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed when the malicious data is being viewed using the "View in browser" feature.
The vulnerability is confirmed in version 2.2.0. Other versions may also be affected.
|