Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft Windows XP HCP URI Handler Abuse Vulnerability

The following example were submitted:

By using the 'hcp:' protocol, it's possible to launch this from a link. The
filename can also include wild cards. Thus, the following link will delete
all files in the 'C:\windows\' directory when the launched window is closed.
(normal file permissions still apply as usual). Sub-directories are not
deleted.

hcp://system/DFS/uplddrvinfo.htm?file://c:\windows\*







 

Privacy Statement
Copyright 2008, SecurityFocus