|
Centrinity FirstClass Client Bookmark Window File Execution Vulnerability
FirstClass client is reported prone to a vulnerability that may allow remote attackers to cause local arbitrary files to be executed. An unspecified field in the FirstClass bookmark management window is not properly sanitized for user-supplied input and URI input can be passed to the Windows ShellExecute API. This may be a serious issue if through other means the attacker can cause a malicious file to be placed on the client filesystem and later execute it. FirstClass 8.0 is reported vulnerable to this issue. |
|
|
Privacy Statement |