There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer audio black screen boot bsod computer connection crash css dell display driver drivers email error ethernet excel explorer firefox firefox 3 game hard drive internet internet explorer itunes laptop lcd linux malware network networking nvidia outlook outlook 2003 outlook express partition printer problem router slow software sound trojan usb video virus vista windows windows xp wireless
Software Development
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Software & Hardware > Software Development >
Flaw Could Enable Web Page to Launch Visual FoxPro 6.0 Application Without Warning: S


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator with 18,502 posts.
 
Join Date: Mar 2001
Location: Bradford, England
04-Sep-2002, 04:01 PM #1
Exclamation Flaw Could Enable Web Page to Launch Visual FoxPro 6.0 Application Without Warning: S
Hiya

In general, when an product installs, it should register itself with
Internet Explorer. This allows the product to specify how Internet
Explorer should handle files associated with it when referenced from
a web page - for instance, it allows the product to specify whether
the user should be presented with a warning dialogue before such a
file is opened.

Visual FoxPro 6.0 does not perform this registration, and this gives
rise to a situation in which a web page could automatically launch a
Visual FoxPro application (i.e., an .app file). In most cases, this
would not result in a security vulnerability - because of the way
Visual FoxPro 6.0 evaluates file names, FoxPro itself could be
started but the .app file would typically not run. However, if the
filename of the application were constructed in a particular way, a
second error (associated with how Visual FoxPro 6.0 evaluates
application filenames) could not only start FoxPro but allow the
application to execute.

The vulnerability could be exploited by creating a web page that
references a Visual FoxPro application, and either hosting it on a
web site or sending it to a user as an HTML mail. If the user had
installed Visual FoxPro 6.0 - or had installed a product that
includes the Visual FoxPro 6.0 runtime - and the filename of the
application was constructed in a particular way, the application
would execute. This would enable the application to not only
interrogate databases, but also issue system commands in the user's
security context

Maximum Severity Rating: Moderate

Affected Software:

Microsoft Visual FoxPro 6.0


Download locations for this patch

Microsoft Visual FoxPro 6.0:


http://www.microsoft.com/downloads/R...eleaseID=42297

http://www.microsoft.com/technet/tre...n/ms02-049.asp

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:16 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.