Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netsc

看板Bugtraq作者時間18年前 (2007/10/10 01:46), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/9 (看更多)
these work inside OE, default with html turned off they do not work when clicked from a normal local html. ----- Original Message ----- From: "Thierry Zoller" <Thierry@Zoller.lu> To: <bugtraq@securityfocus.com>; <full-disclosure@lists.grok.org.uk> Sent: Saturday, October 06, 2007 8:06 AM Subject: Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape,Miranda, Skype > Dear All, > > mailto:test%../../../../windows/system32/calc.exe".cmd > I would deem 1 and 3 as resonable (intented) behaviour. > >>2) now do the very same thing on a system with Windows XP and IE7. >>calc.exe is executed. > Confirmed here, that's definately a Problem, and should be linked to > the Windows URI Handler. (IMHO) > > > The behaviour is this : > The extension determines the handler to use to shell > "../../../../windows/system32/calc.exe" > > Example : > mailto:test%../../../../windows/system32/calc.exe".cmd > Usese the cmd handler to open calc (which executes) > > mailto:test%../../../../windows/system32/calc.exe".txt > uses notepad and tries to open calc. > > Somethings definately broken with the URI handler (imho) > > > -- > http://secdev.zoller.lu > Thierry Zoller > Fingerprint : 5D84 BFDC CD36 A951 2C45 2E57 28B3 75DD 0AC6 F1C7 > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ >
文章代碼(AID): #172xvQ00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 4 之 9 篇):
文章代碼(AID): #172xvQ00 (Bugtraq)