Brett Moore has reported some vulnerabilities in SiteKiosk, which can be exploited by malicious, local users to bypass certain security restrictions.
1) An error exists in the handling of certain skins, where the URL is displayed in the title bar of the main window. This can be exploited to access the file system with an explorer window by setting the location to "ABOUT:hello<a href=\>click here</a>" and clicking on the link in the title bar.
2) Site Kiosk uses ActiveX controls that expose methods, which can be used by a SiteKiosk user to read and download any file from the system with permissions of the SiteKiosk user.
The vulnerabilities are reported in versions prior to 6.5.150.
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to firstname.lastname@example.org