CVE-2003-0907

Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.

Date published : 2004-04-16

http://www.securityfocus.com/bid/10119

http://marc.info/?l=bugtraq&m=108196864221676&w=2