aMSN does not check SSL certificate before sending MSN user credentials. An attacker is able to obtain MSN username and password with a spoofed certificate and no alert is generated to the user. This vulnerability was found in aMSN 0.97.2. Other versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78682/amsn-ssl.txt
Source: https://packetstormsecurity.com/files/78682/aMSN-SSL-Certification-Vulnerability.html

