[35004] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Internet explorer .clsid vulnerability

daemon@ATHENA.MIT.EDU (roozbeh afrasiabi)
Sat May 22 18:57:40 2004

Date: 22 May 2004 02:45:02 -0000
Message-ID: <20040522024502.30155.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: roozbeh afrasiabi <roozbeh_afrasiabi@yahoo.com>
To: bugtraq@securityfocus.com

In-Reply-To: <8B32EDC90D8F4E4AB40918883281874D523591@pivxwin2k1.secnet.pivx.com>

>This is actually a behavior that is part of Windows Explorer, not
Internet Explorer. I think we have covered this in the past on lists as
well. If it is not already documented somewhere it should be, as this is
how Windows file queries (inside IE) are performed on the local file
system.


The following would execute netmeeting on ie.6 when tested from an 
internet site but it dose not work on ie.6+sp1 .

<a href="c:\x.{3E9BAF2D-7A79-11d2-9334-0000F875AE17}">here</a>
<a href="c:\.{3E9BAF2D-7A79-11d2-9334-0000F875AE17}">here</a>


Thanx for the info ---> me gone searching fo' more

home help back first fref pref prev next nref lref last post