Hi Rostik,

There is no need to switch over to FF yet, because this thing is an ongoing saga, and there are a couple of bugs involved there. It is almost like some religious war between the developers of both camps IE versus FF. Read what I write here: http://madamemmastent.smfforfree.com/index.php?topic=1542.0 (seen from my experience with Flock browser)
and the info in this link here: http://msinfluentials.com/blogs/mobilejesper/archive/2007/07/26/the-protocol-handler-saga-continues-say-what-secunia.aspx
That means it is not a problem easily to be solved, and those with FF and IE7 on their system are not secure, even if their XP2 is fully patched. All aspects of this exploit should be fully investigated.
Good that you posted about it, these are very important items, I think the problem arose when things were rearranged from IE6 to IE7.
Rostik - Firefox doesn’t do any additional processing on the schemes in question.
It just passes them to ShellExecute, like every other scheme.
It’s actually Windows that processes them differently,
and in particular this processing changed with the IE7 upgrade.
In particular, try the following two URIs in “Start > Run …” on an XP system with IE7 installed:

mailto:test%../../../../windows/system32/calc.exe".cmd

mailto:test../../../../windows/system32/calc.exe".cmd

The former launches calc.exe, while the latter launches the default mailto: handler.

Damian