Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: MS Outlook javascript parsing bug

MS Outlook javascript parsing bug

From: Mikael Olsson <mikael.olsson_at_ENTERNET.SE>
Date: Tue, 9 Nov 1999 18:47:20 +0100

It seems that MS Outlook 8.5.5104.6 screws up when displaying the
following string in a mail message:

<javascript:location.reload()>

Note that you do NOT need to click it, just displaying the mail
message will crash Outlook.

The results are completely unpredictable, everything from hanging,
crashing or complaining about not being able to display a
particular font or complaining about being out of memory?!?!?!

Anyone care to do anything fun with it other than spam mailing
people to create a big 'ole DoS? :-)

Just my $.02
/Mike

--
Mikael Olsson, EnterNet Sweden AB, Box 393, S-891 28 ÖRNSKÖLDSVIK
Phone: +46-(0)660-105 50           Fax: +46-(0)660-122 50
Mobile: +46-(0)70-248 00 33
WWW: http://www.enternet.se        E-mail: mikael.olsson@enternet.se
Received on Nov 09 1999
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos