Changeset 1535

Show
Ignore:
Timestamp:
01/23/08 17:39:54 (7 months ago)
Author:
jose
Message:

[phoneyc]
overflow in Lycos FileUploader? Module 2.x
vuln module and exploit code

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • phoneyc/trunk/ActiveX.py

    r1534 r1535  
    5454        self.clsid['361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2'] = RtspVaPgCtrl() 
    5555        self.clsid['AD315309-EA00-45AE-9E8E-B6A61CE6B974'] = Toshiba() 
     56        self.clsid['C36112BF-2FA3-4694-8603-3B510EA3B465'] = FileUploader() 
    5657 
    5758        self.clsname = {} 
     
    7374        self.clsname['RtspVaPgDecoder.RtspVaPgCtrl.1'] = RtspVaPgCtrl() 
    7475        self.clsname['MeIpCamX.RecordSend.1'] = Toshiba() 
     76        self.clsname['FileUploader.FUploadCtl.1'] = FileUploader() 
    7577 
    7678        # set up the pure JScript version 
     
    361363        self.cve_id = ('CVE-NOMATCH', ) 
    362364        self.description = 'Toshiba Surveillance (Surveillix) RecordSend Class (MeIpCamX.DLL 1.0.0.4)' 
    363  
     365         
     366class FileUploader(ActiveX): 
     367    def __init__(self): 
     368        self.js_src = self.load_js_src('FileUploader.js') 
     369        self.classname = 'FileUploader' 
     370        self.cve_id = ('CVE-NOMATCH', ) 
     371        self.description = 'Lycos FileUploader Module 2.x' 
     372