Re[2]: 0day: mIRC pwns Windows

看板Bugtraq作者時間18年前 (2007/10/04 23:59), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Dear Gavin Hanover, In this very case it's really seems to be mIRC problem ("unfiltered shell characters"). It doesn't depend on URL handler and will work with any valid URL handler. You can reproduce same vulnerability by entering http:%xx../../../../../../../../../../../windows/system32/calc.exe".bat Exploitable under Windows XP, not exploitable under Vista. --Wednesday, October 3, 2007, 11:59:45 PM, you wrote to jinc4fareijj@hotmail.com: GH> is this a mirc bug or a mail client bug? >> mailto:%xx../../../../../../../../../../../windows/system32/calc.exe".bat >> -- ~/ZARAZA http://securityvulns.com/
文章代碼(AID): #171GtF00 (Bugtraq)
文章代碼(AID): #171GtF00 (Bugtraq)