[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <40F1125D.1090402@hmc.edu>
From: jruderman at hmc.edu (Jesse Ruderman)
Subject: MSN Messenger is vulnerable to the shell: hole
Clicking a shell:windows\notepad.exe link in MSN Messenger 6.2.0137
launches Notepad. MSN Messenger even recognizes shell: as a protocol
and helpfully hyperlinks the URL.
Ctrl+clicking a shell:windows\notepad.exe link in Microsoft Word
10.2627.3311 launches Notepad.
What others Windows programs (browsers, e-mail clients, IM clients, word
processors, etc.) are vulnerable to the shell: hole?
Powered by blists - more mailing lists