BUG FIX Remote compromise of Internet Explorer Service Pack 2 XP SP2

"Michael Evanchik" <[email protected]> Mon, 27 Dec 2004 17:53:57 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq,gmane.comp.security.ntbugtraq,gmane.comp.security.full-disclosure
Organization MichaelEvanchik.com
Message-ID <[email protected]>
Had a mistake in my code o well.  Works now

PoC: http://www.michaelevanchik.com/security/microsoft/ie/xss/index.html

http://www.michaelevanchik.com/security/microsoft/ie/xss/writehta.txt <--  avp's should add this



Here is some new adodb code AVP's should add.  No longer needed to connect to external source.  Malicious recordset can be built locally.


www.michaelevanchik.com