Overview
A remotely exploitable vulnerability exists in the Help and Support Center (HCP). An attacker could compromise the victim's system by tricking them into visiting a malicious web site, or viewing a malicious email message.
Description
A failure to filter special characters, such as quotes, from HCP URLs could lead to inject code into the . By tricking a victim in to visiting a malicious web site, or viewing a malicious email, the remote attacker could exploit this vulnerability to remotely execute code in the "MyComputer" zone. The following systems are affected by this issue:
|
Impact
A remote attacker could exploit this vulnerability to execute code in the "MyComputer" zone with the privileges of the current user. |
Solution
Apply a patch from the vendor |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Jouko Pynnönen for reporting this vulnerability.
This document was written by Jason A Rafail.
Other Information
CVE IDs: | CVE-2003-0907 |
Severity Metric: | 35.10 |
Date Public: | 2004-04-13 |
Date First Published: | 2004-04-14 |
Date Last Updated: | 2004-04-14 06:54 UTC |
Document Revision: | 3 |