Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netsc

看板Bugtraq作者時間18年前 (2007/10/10 00:59), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/9 (看更多)
----- Original Message ----- From: "Thierry Zoller" <Thierry@Zoller.lu> > The user clicks on a mailto link, is that untrusted code? Depends on where the link comes from. If it's a shortcut on the users desktop no it's not untrusted, if it's in a PDF file you received in your email then yes it's untrusted. > Anyways, the mailto link > POST IE7 has a flaw/threat/vulnerablity it hasn't had PRE IE7. > The problem here is the root cause, the root cause is that IE7 Ok I'm game, so then show me this exploit without having Acrobat on your system. IE7 handles mailto links in untrusted web pages. Put the mailto link in an untrusted html page and make it work with IE7. Geo.
文章代碼(AID): #172xDV00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 3 之 9 篇):
文章代碼(AID): #172xDV00 (Bugtraq)