Re: [Full-disclosure] Lotus expeditor rcplauncher uri handler vulnerability

2008-04-24 Thread Nate McFeters
Very nice, looks a lot like some of my work in URI handler abuse. -Nate On 4/24/08, Thomas Pollet <[EMAIL PROTECTED]> wrote: > > Hello, > > I have found that the lotus expeditor rcplauncher as installed by lotus > symphony and possibly other products, registers a cai: uri handler. > This handler

[Full-disclosure] Lotus expeditor rcplauncher uri handler vulnerability

2008-04-24 Thread Thomas Pollet
Hello, I have found that the lotus expeditor rcplauncher as installed by lotus symphony and possibly other products, registers a cai: uri handler. This handler executes "D:\Program Files\IBM\Lotus\Symphony\framework\rcp\rcplauncher.exe" -config notes -com.ibm.rcp.portal.app.ui#openCA "%1" the rcpl