PDA

View Full Version : RemoteDocs R-Viewer Code Execution and Sensitive Information Disclosure



newsbot
20-09-2007, 05:25 PM
RemoteDocs R-Viewer is "a secure document viewer used by remotedocs.com". There exists a design flaw in RemoteDocs R-Viewer where code can be executed upon opening the RDZ file without any knowlege or warning to the user. Additionally, temporary files are not properly removed of disk exposing the encrypted data.

http://www.securiteam.com/windowsntfocus/5NP0N00MKA.html