Overview
A remotely exploitable vulnerability exists in the Help and Support Center (HCP). An attacker could compromise the victim's system by tricking them into visiting a malicious web site, or viewing a malicious email message.
Description
| A failure to filter special characters, such as quotes, from HCP URLs could lead to inject code into the . By tricking a victim in to visiting a malicious web site, or viewing a malicious email, the remote attacker could exploit this vulnerability to remotely execute code in the "MyComputer" zone. The following systems are affected by this issue: 
 | 
Impact
| A remote attacker could exploit this vulnerability to execute code in the "MyComputer" zone with the privileges of the current user. | 
Solution
| Apply a patch from the vendor | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to Jouko Pynnönen for reporting this vulnerability.
This document was written by Jason A Rafail.
Other Information
| CVE IDs: | CVE-2003-0907 | 
| Severity Metric: | 35.10 | 
| Date Public: | 2004-04-13 | 
| Date First Published: | 2004-04-14 | 
| Date Last Updated: | 2004-04-14 06:54 UTC | 
| Document Revision: | 3 |