Web Hack List

Other nomination

Code Execution via XSS

Saved XSS turned into code execution. Inject ?--><script>c=new/**/ActiveXObject('WScript.Shell');c.Run('calc.exe');</script> so it lands in a page the user saves to disk; reopened, the file runs in the Local Machine Zone and the ActiveX fires. The payload only materialises after saving, so content-inspecting proxies, firewalls and AV never see it. IE6 and IE7.

Record

Researcher
MustLive
Published by
securityvulns.ru

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of MustLive, first published at the original source. Preserved copies are kept so the citation survives its host.