Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2057


Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2057
Last Modified 07 Mar 2011 09:35:05
Published 26 Apr 2006 04:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.

Vulnerable Systems


  • Avant Force Avant Browser 10.1 Build 17

  • Microsoft Ie 6.0

  • Microsoft Outlook 2003

  • Mozilla Firefox 1.0.6


VUPEN - ADV-2006-1538

BUGTRAQ - 20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit


XF - office-mailto-obtain-information(26118)

Last Updated: 27 May 2016 10:42:19