CVE-2007-4960 Information

Description

Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler as used in Internet Explorer and possibly Firefox allows remote attackers to obtain sensitive information via a ‘\ ’ (double-quote space) sequence followed by the -autologin and -loginuri arguments which cause the handler to post login credentials and software installation details to an arbitrary URL.

Reference

http://secunia.com/advisories/26845 http://www.gnucitizen.org/blog/ie-pwns-secondlife http://www.securityfocus.com/archive/1/479698/100/0/threaded http://www.vupen.com/english/advisories/2007/3188 https://exchange.xforce.ibmcloud.com/vulnerabilities/36651

Share on: