The Mozilla application platform currently has an unpatched input
validation flaw which allows you to specify arbitrary command line
arguments to any registered URL protocol handler process. Jesper
Johansson already detailed parts of this on his blog on July 20,
http://msinfluentials.com/blogs/j...
validation flaw which allows you to specify arbitrary command line
arguments to any registered URL protocol handler process. Jesper
Johansson already detailed parts of this on his blog on July 20,
http://msinfluentials.com/blogs/j...
[ more ]