RE: Microsoft MCWNDX.OCX ActiveX buffer overflow

2003-08-14 Thread Drew Copley
rol for scripting on webpages in the Internet Zone. > -Original Message- > From: xenophi1e [mailto:[EMAIL PROTECTED] > Sent: Wednesday, August 13, 2003 10:51 AM > To: [EMAIL PROTECTED] > Subject: Re: Microsoft MCWNDX.OCX ActiveX buffer overflow > > > In-Reply-To: <

RE: Microsoft MCWNDX.OCX ActiveX buffer overflow

2003-08-14 Thread Oliver Lavery
<PARAM name="FileName" VALUE="' + buf +'">'); WndDoc.write('</OBJECT>'); WndDoc.write('</BODY>'); WndDoc.write('</HTML>'); Cheers, ~ol > -Original Message- > From: Drew Copley [mailto:

Microsoft MCWNDX.OCX ActiveX buffer overflow

2003-08-14 Thread Tri Huynh
Microsoft MCWNDX.OCX ActiveX buffer overflow = PROGRAM: MICROSOFT MCIWNDX.OCX ACTIVEX BUFFER OVERFLOW HOMEPAGE: www.microsoft.com VULNERABLE VERSIONS: MCWNDX is an ActiveX shipped with Visual Studio 6 to support multimedia programming

Re: Microsoft MCWNDX.OCX ActiveX buffer overflow

2003-08-14 Thread xenophi1e
In-Reply-To: <[EMAIL PROTECTED]> Does anyone know what the guid for this control is? I don't have it on XP with Visual Studio 6 installed. Could this be the same as the Microsoft Multimedia Control, aka MCI32.OCX? Cheers, ~ol > Microsoft MCWNDX.OCX ActiveX b

RE: [Full-Disclosure] Microsoft MCWNDX.OCX ActiveX buffer overflow

2003-08-14 Thread Jason Coombs
n Coombs [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Thor Larholm Sent: Wednesday, August 13, 2003 8:22 AM To: Tri Huynh; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: [Full-Disclosure] Microsoft MCWNDX.OCX ActiveX buffer overflow