BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: [Full-disclosure] SEC-Consult SA 20051025-0 :: Snoopy Remote Code Execution Vulnerability Oct 27 2005 02:14PM
SEC Consult Research (research sec-consult com)
On Thu, October 27, 2005 10:12 am, Florian Weimer said:
> Have you considered in your analysis that malicious servers might
> return HTTP redirects which contain suitable URLs? This requires that
> the offsiteok member is set to true, though, because in the version I
> looked at, only http:// URLs ...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus