+-----------------------------------------------------------------------------+ | noptrix.net - Public Security Advisory | +-----------------------------------------------------------------------------+ Date: ----- 08/17/2011 Vendor: ------- Skype Limited - http://www.skype.com/ Affected Software: ------------------ Software: Skype Version: <= 5.5.0.113 Affected Platforms: ------------------- Windows (XP, Vista, 7) Vulnerability Class: -------------------- HTML/(Javascript) code injection Description: ------------ Skype suffers from a persistent code injection vulnerability due to a lack of input validation and output sanitization of following profile entries: - home - office - mobile Proof of Concept: ----------------- The following HTML codes can be used to trigger the described vulnerability: --- SNIP --- Home Phone Number: INJECTION HERE Office Phone Number: