hacking security forum

[Full-Disclosure] msxml3.dll Parsing Error Crashes Internet Explorer Remotely Upon Refresh

From: Rafel Ivgi, The-Insider <theinsider@012.net.il>
Date: Mon May 10 2004 - 14:27:40 EDT

msxml3.dll crashes after refreshing a page which contains & inside a
link/value
For Example : <Ref href = "&"/>
This is due to a parsing error in msxml3.dll.

Version Details:
---------------------
I.E Version: 6.0.2600.0
ModVer: 8.10.8308.0
Module name: msxml3.dll
Offset: 000b8c10

Stack Dump:
-----------------
EAX=01CEE800
EDI=01D02580
EBX=00000000
EBP=02C3F3E4
ECX=00000000
ESP=02C3FC74
EDX=02D91364
EIP=02E18C10
ESI=00000000
DS:00000004 GS:0000 ES:0023 SS:0023 CS:001B

Live Example:
http://theinsider.deep-ice.com/xmlcrash.xml
AND REFRESH...

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Mon May 10 14:26:05 2004

This archive was generated by hypermail 2.1.8 : Mon May 10 2004 - 15:05:23 EDT

Custom Search