Thursday, January 1, 2009

Borland Code Gear URI Handler XSS

This is one of some vulnerabilities i found in the most recent Borland Code Gear.
It consists in a XSS and it exist, becouse of a bad uri handler (bds://).

You can find this vuln, in all versions of Borland Codegear until Codegear 2009.

Ex: bds:/../../../../../WINDOWS/NOTEPAD.EXE
Etc.

Happy new year!

Really great things will be posted soon!
Stay tuned!