Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re[2]: 0day: mIRC pwns Windows Oct 04 2007 11:12AM
3APA3A (3APA3A SECURITY NNOV RU)
Dear Gavin Hanover,

In this very case it's really seems to be mIRC problem ("unfiltered
shell characters"). It doesn't depend on URL handler and will work with
any valid URL handler. You can reproduce same vulnerability by entering

http:%xx../../../../../../../../../../../windows/system32/c...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus