|
FirstClass Client Bookmark Files Can Launch Local Programs
|
|
Secunia Advisory:
|
SA14898
|
|
|
Release Date:
|
2005-04-08
|
|
Last Update:
|
2005-04-14
|
|
Popularity:
|
8,159 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | FirstClass Client 8.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: dila has reported a vulnerability in FirstClass, which can be exploited by malicious people to execute arbitrary commands on a vulnerable system.
The vulnerability is caused due to lack of restrictions on URLs in Internet bookmarks. This can be exploited to supply UNC paths in Internet bookmark files to local or network resources. The commands will be executed when a user clicks on the bookmark file.
This issue is similar to:
SA10556
This has been reported in FirstClass Client version 8.0.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|