The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  IE, Outlook run malicious commands without scripting
Time: 09:00 EST/14:00 GMT | News Source: The Register | Posted By: Byron Hinson

An attacker can run arbitrary commands on Windows machines with a simple bit of HTML, an Israeli security researcher has demonstrated. The exploit will work with IE, Outlook and OutlooK Express even if active scripting and ActiveX are disabled in the browser security settings. The problem here is data binding, an old 'feature' going back to IE4 in which a data source object (DSO) is bound to HTML. Using an XML data source, the researchers operating a Web site called GreyMagic Software came up with a simple example in which a few lines will cause Windows to launch the calculator application thus:

Write Comment
Return to News

  Displaying 576 through 576 of 576
Prev | First
  The time now is 12:14:48 PM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/11/2025 10:57:17 PM
https://justpaste.me/ZmMw3
https://justpaste.me/Z2iR2
https://justpaste.me/ZzUN
https://justpaste.me/YuKg3
https://justpaste.me/Z48d2
https://justpaste.me/aDVN1
https://justpaste.me/a6xI1
https://justpaste.me/Zdkt4
https://justpaste.me/a24M3
https://justpaste.me/YmIU4

Write Comment
Return to News
  Displaying 576 through 576 of 576
Prev | First
  The time now is 12:14:48 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *