HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via a session (HAW) file, which can be automatically opened using Internet Explorer.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/454388/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/21594 | vdb entry |
http://secunia.com/advisories/23366 | third party advisory |
http://securityreason.com/securityalert/2045 | third party advisory |
http://www.vupen.com/english/advisories/2006/5013 | vdb entry |