[sldev] MAJOR/CRITICAL exploit for webbrowsers and SL? (Lawson
English)
Argent Stonecutter
secret.argent at gmail.com
Tue Sep 18 10:41:50 PDT 2007
This exploit only works on Windows. On UNIX the calling application
(shell, etc) splits the command line up into words, so the quoting
exploit would not work unless the calling application is stupendously
stupid and passes the input unfiltered to a shell (in which case
there are many juicier exploits to be found).
More information about the SLDev
mailing list