Back to search
CVE-2006-2312
Published: May 19, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20060521 Skype - URI Handler Command Switch Parsing
mailing-list
x_refsource_FULLDISC
18038
vdb-entry
x_refsource_BID
VU#466428
third-party-advisory
x_refsource_CERT-VN
ADV-2006-1871
vdb-entry
x_refsource_VUPEN
skype-uri-handler-file-access(26557)
vdb-entry
x_refsource_XF
20060521 Skype - URI Handler Command Switch Parsing
mailing-list
x_refsource_BUGTRAQ
25658
vdb-entry
x_refsource_OSVDB
20154
third-party-advisory
x_refsource_SECUNIA
http://www.skype.com/security/skype-sb-2006-001.html
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now