Other nomination
Code Execution via XSS
Saved XSS turned into code execution. Inject ?--><script>c=new/**/ActiveXObject('WScript.Shell');c.Run('calc.exe');</script> so it lands in a page the user saves to disk; reopened, the file runs in the Local Machine Zone and the ActiveX fires. The payload only materialises after saving, so content-inspecting proxies, firewalls and AV never see it. IE6 and IE7.
Record
- Researcher
- MustLive
- Published by
- securityvulns.ru
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of MustLive, first published at the original source. Preserved copies are kept so the citation survives its host.