Re: [Full-disclosure] Links smbclient command execution

2006-11-29 Thread Mikulas Patocka
On Wed, 29 Nov 2006, Mikulas Patocka wrote: Hi I fixed it in Links 1.00pre19 (at http://artax.karlin.mff.cuni.cz/~mikulas/links/download/) and Links 2.1pre25 (at http://links.twibright.com/download/) --- please check it. I changed it to refuse '' and ';' from file path. I hope that

Re: [Full-disclosure] Links smbclient command execution

2006-11-28 Thread Mikulas Patocka
Hi I fixed it in Links 1.00pre19 (at http://artax.karlin.mff.cuni.cz/~mikulas/links/download/) and Links 2.1pre25 (at http://links.twibright.com/download/) --- please check it. I changed it to refuse '' and ';' from file path. I hope that user name and password at smbclient command line

[Full-disclosure] Links smbclient command execution

2006-11-14 Thread Teemu Salmela
Links smbclient command execution - There is a flaw in the Links web browser, that allows malicious web sites to execute smbclient commands on the victim's machine. This flaw makes it possible to read any file from the