Security Advisory

CVE-2008-1805

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2008-06-06 22:00:00
Last updated 2024-08-07 08:32:01
Assigner mitre
State PUBLISHED

Description

Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.