The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  IE, Outlook run malicious commands without scripting
Time: 09:00 EST/14:00 GMT | News Source: The Register | Posted By: Byron Hinson

An attacker can run arbitrary commands on Windows machines with a simple bit of HTML, an Israeli security researcher has demonstrated. The exploit will work with IE, Outlook and OutlooK Express even if active scripting and ActiveX are disabled in the browser security settings. The problem here is data binding, an old 'feature' going back to IE4 in which a data source object (DSO) is bound to HTML. Using an XML data source, the researchers operating a Web site called GreyMagic Software came up with a simple example in which a few lines will cause Windows to launch the calculator application thus:

Write Comment
Return to News

  Displaying 151 through 151 of 151
Prev | First
  The time now is 5:58:52 PM ET.
Any comment problems? E-mail us
#151 By 4240821 (193.36.231.111) at 7/3/2024 10:56:14 AM
https://sexonly.top/get/b142/b142fqzxpsdqssycvto.php
https://sexonly.top/get/b297/b297ararudiypjxcsrr.php
https://sexonly.top/get/b330/b330adacjjwylbgxoqq.php
https://telegra.ph/Onlyfans-alternative-Freeuse-HellyVonValentine-Leaked-01-29
https://sexonly.top/get/b788/b788uzbdxbzeycuoiww.php
https://sexonly.top/get/b974/b974kzdwjrqtrqmynvt.php
https://www.google.com/maps/d/edit?mid=1GkHNHFa45Ynq9GfIgO5T9Jq9drBMW2c
https://sexonly.top/get/b135/b135zfrfcgugbpxhufb.php
https://sexonly.top/get/b754/b754wobajdxfcxfcvxz.php
https://sexonly.top/get/b894/b894thitodyxqapkxiw.php

Write Comment
Return to News
  Displaying 151 through 151 of 151
Prev | First
  The time now is 5:58:52 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *