CVE-2006-2312

Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:skype:skype:*:*:*:*:*:*:*:*
cpe:2.3:a:skype:skype:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-05-19 21:02

Updated : 2024-02-13 17:47


NVD link : CVE-2006-2312

Mitre link : CVE-2006-2312

CVE.ORG link : CVE-2006-2312


JSON object : View

Products Affected

skype

  • skype

microsoft

  • windows
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')