CVE-2007-4960 Information
Feb 14, 2021
cve
Description
Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler as used in Internet Explorer and possibly Firefox allows remote attackers to obtain sensitive information via a ‘\ ’ (double-quote space) sequence followed by the -autologin and -loginuri arguments which cause the handler to post login credentials and software installation details to an arbitrary URL.
Reference
http://secunia.com/advisories/26845 http://www.gnucitizen.org/blog/ie-pwns-secondlife http://www.securityfocus.com/archive/1/479698/100/0/threaded http://www.vupen.com/english/advisories/2007/3188 https://exchange.xforce.ibmcloud.com/vulnerabilities/36651
Share on: