Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Centrinity FirstClass Client Bookmark Window File Execution Vulnerability

FirstClass client is reported prone to a vulnerability that may allow remote attackers to cause local arbitrary files to be executed.

An unspecified field in the FirstClass bookmark management window is not properly sanitized for user-supplied input and URI input can be passed to the Windows ShellExecute API.

This may be a serious issue if through other means the attacker can cause a malicious file to be placed on the client filesystem and later execute it.

FirstClass 8.0 is reported vulnerable to this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus