notepad-plus-plus-legacy/PowerEditor
Don HO 0f936707a2 [EU-FOSSA] Fix a security issue: RCE via unsanitized command line in "Open containing folder"
Summary of the Issue:
A remote code execution (RCE) vulnerability was found when a user opens a crafted containing folder in the command line. Code execution is possible by injecting a & followed by system commands into the name of the folder.

Steps to reproduce:
Download the attached archive on Windows: unzip_me.zip (F404758)
Unzip it and navigate into it
Open the txt file inside with Notepad++
Go to File -> Open containing folder -> cmd

Impact statement:
Successful exploitation of this vulnerability would allow an attacker to remotely execute arbitrary commands on the victim's computer.
2019-01-14 20:20:19 +01:00
..
bin Notepad++ 7.6.2 release Gilet Jaune Edition 2019-01-01 02:46:17 +01:00
gcc MinGW GCC update 2016-10-31 14:03:29 +01:00
installer Notepad++ 7.6.2 release Gilet Jaune Edition 2019-01-01 02:46:17 +01:00
misc/chameleon Remove the old icon 2016-09-21 09:06:22 +02:00
scintilla.original.forUpdating Create scintillaUpdatingWorkFlow.txt 2015-07-25 01:35:43 +02:00
src [EU-FOSSA] Fix a security issue: RCE via unsanitized command line in "Open containing folder" 2019-01-14 20:20:19 +01:00
Test/FunctionList Add unit tests for function list feature 2018-04-13 12:46:03 +02:00
visual.net Update uchardet to 0.0.6 to improve UTF-8 detection quality 2018-11-09 13:49:58 +01:00