I'm too lazy to investigate further but my guess is that if there is a vulnerability here it has something to do with dns name spoofing.