>> Skype for Windows Remote URL Handling Arbitrary File Transfer Vulnerability
Title : Skype for Windows Remote URL Handling Arbitrary File Transfer Vulnerability VUPEN ID : VUPEN/ADV-2006-1871 CVE ID : CVE-2006-2312
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-05-20
Technical Description
A vulnerability has been identified in Skype, which may be exploited by attackers to download arbitrary files from a vulnerable system. This flaw is due to an error in the Skype URI handler when processing specially crafted parameters, which could be exploited by remote attackers to initiate a file transfer from an affected system, by tricking a user into following a malicious link.