Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-0027
Description:The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Test IDs: 1.3.6.1.4.1.25623.1.0.900227  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-0027
Bugtraq: 20100209 ZDI-10-016: Microsoft Windows ShellExecute Improper Sanitization Code Execution Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/509470/100/0/threaded
Cert/CC Advisory: TA10-040A
http://www.us-cert.gov/cas/techalerts/TA10-040A.html
http://www.zerodayinitiative.com/advisories/ZDI-10-016/
Microsoft Security Bulletin: MS10-002
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-002
Microsoft Security Bulletin: MS10-007
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-007
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8464
XForce ISS Database: ie-url-code-execution(55773)
https://exchange.xforce.ibmcloud.com/vulnerabilities/55773




© 1998-2025 E-Soft Inc. All rights reserved.