Bugtraq mailing list archives

Re: IE5 allows executing programs


From: broodahs () ZERG COM (Haxor, Wikit)
Date: Thu, 16 Sep 1999 12:56:30 -0700


another twist on this ie5 exploit

Mplayer (mplayer.com) offers a service where players can find other players
to play games.  With a Plus (pay) account, you can force users to view a url
when entering a game lobby.  Just have them look at a page with the ie5
exploit and boom... they have no choice when they enter the game lobby but
to get the exploit.  mplayer uses the ie browser ocx's so if you have ie5
then you will be exploited.  or add in the ie5 java boxes to ask for
username/password and you get a plus account...... for free.  just a little
more mayhem to cause and more reason for a patch to be released


Current thread: