Skype skype: URI Handling /Datapath Argument Injection Settings Manipulation (credentialed check)

Last Updated: March 16, 2010

Synopsis : The remote Skype client is affected by an information disclosure vulnerability. Description : According to its timestamp, the version of Skype installed on the remote Windows host fails to sanitize input in its URI handler to its ‘/Datapath’ argument, which specifies the location of the Skype configuration files and security policy. If an attacker can trick a user on the affected system into clicking on a specially crafted link, he may be able to have the client use a Datapath location on a remote SMB share.

Read more:
Skype skype: URI Handling /Datapath Argument Injection Settings Manipulation (credentialed check)

CodeRed Center

Visit EC-Council's CodeRed Center

Leave a Comment

iClass

Attend online, live security training anywhere, anytime.

Hacker Halted 2009

Attend Hacker Halted 2009 USA Conference in Miami, Florida.