Microsoft Outlook Mailto Parameter Quoting Zone Bypass Vulnerability

It is possible to influence Outlook invocation parameters by including a '"' string in the mailto URI.

The following proof of concept is available:


 

Privacy Statement
Copyright 2010, SecurityFocus