Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re[2]: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Oct 06 2007 03:06PM
Thierry Zoller (Thierry Zoller lu)
Dear All,

mailto:test%../../../../windows/system32/calc.exe".cmd
I would deem 1 and 3 as resonable (intented) behaviour.

>2) now do the very same thing on a system with Windows XP and IE7.
>calc.exe is executed.
Confirmed here, that's definately a Problem, and should be linked to
the Windows URI H...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus