Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.
| Software | From | Fixed in |
|---|---|---|
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build150 | 6.0_build150.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build155 | 6.0_build155.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build153 | 6.0_build153.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build152 | 6.0_build152.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build149 | 6.0_build149.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build151 | 6.0_build151.x |
| gadu-gadu / gadu-gadu_instant_messenger | 6.0_build154 | 6.0_build154.x |