Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Multiple Microsoft Internet Explorer crossite scripting bugs

  FW: [Unpatched] Shell and Drag'n'Drop vulnerabilities

  MSIE Overly Trusted Location Variant Method Cache Vulnerability

  IE Shell URI Download and Execute, POC

  Media Preview Script Execution Vulnerability

From:Paul <paul_(at)_greyhats.cjb.net>
Date:13.07.2004
Subject:MSOE Javascript Execution Vulnerability



Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net

Outlook Express Window Opener Script Execution Vulnerability

[Tested]
Microsoft Outlook Express version 6.0.2800.1123.
Microsoft Windows XP sp2

[Discussion]
Microsoft Outlook Express is prone to a vulnerability which will allow javascript to execute in
the message window. Outlook Express uses a webbrowser control to view email messages, with all
features except javascript, objects, and a couple more. Apparently, it only filters out stuff in
the window.document object. If something were to access any other components of the window
object, it would be given as much access as if the mail message had been an html document opened
in internet explorer.

The example presents the viewer with a link to a javascript page with the target set to
"_blank" (opens the page in a new window). The javascript calls opener.execScript, displaying an
alert with the message body's innerHTML.

[Example]
http://freehost07.websamba.com/greyhats/msoeexecscript.htm

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server