Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2058

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2058
Last Modified 07 Mar 2011 09:35:05
Published 26 Apr 2006 04:06:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2058

Summary

Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.

Vulnerable Systems

Application

  • Avant Force Avant Browser 10.1 Build 17


References

VUPEN - ADV-2006-1538

BUGTRAQ - 20060424 Multiple browsers Windows mailto protocol Office 2003 file attachment exploit

MISC - http://ingehenriksen.blogspot.com/2006/04/office-2003-file-attachment-exploit.html

XF - office-mailto-obtain-information(26118)

SREASON - 785


Last Updated: 27 May 2016 10:42:19