[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] OE - news:// stupid url handler behavior
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: Re: [Full-disclosure] OE - news:// stupid url handler behavior
- From: J4y D33 <jd.security@xxxxxxxxx>
- Date: Thu, 5 Jan 2006 16:32:20 +0100
Have tried it using a windows 2000 professional sp4 workstation with
IE 6.0, although OE has been set to handle the nntp protocol nothing
seems to happen.
Cheers, JD
Morning Wood wrote:
>I doubt this warrants a fix ( nor Advisory ) , but it is realy dumb,
>note the sidebar and titles in OE when testing.
>
>these launch OE from a webpage
>
>1.
>==
>hi
><iframe src=news://omg-h4ck3d\owned height=0 width=0></iframe>
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/