On The Road ZJL

我的博客列表

2008年8月7日星期四

Www.edup.tudelft.nl/~bjwever/advisory iframe.html.php - Skypher

Www.edup.tudelft.nl/~bjwever/advisory iframe.html.php - Skypher:
nternet Explorer IFRAME src&name parameter BoF remote compromise

Contents

[hide]

Vulnerability

There is an exploitable BoF in the FRAME, EMBED and IFRAME tag using the SRC and NAME property. To trigger the BoF you only need this tag in a HTML file: