metasploit-framework/modules/exploits/windows/browser
kernelsmith f1a39c76ed update to ie_execcommand_uaf's info to add ROP info
This module requires the following dependencies on the target for the
ROP chain to function.  For WinXP SP3 with IE8, msvcrt must be present
(which it is on default installs).  For Vista/Win7 with IE8 or Win7
with IE9, ire 1.6.x or below must be installed.
2012-09-19 14:10:02 -05:00
..
adobe_cooltype_sing.rb Older targets confirmed for CoolType SING 2012-09-12 16:51:51 -05:00
adobe_flash_mp4_cprt.rb Merge branch 'rapid7' into http-print-standardization 2012-04-18 08:51:42 -06:00
adobe_flash_otf_font.rb Add Adobe security bulletin references 2012-09-04 00:07:53 -05:00
adobe_flash_rtmp.rb Add Metasploit blogs as references, because they're useful. 2012-09-03 15:57:27 -05:00
adobe_flash_sps.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
adobe_flashplayer_arrayindexing.rb Fix a few mistakes (typos & reference) 2012-06-21 02:32:04 -05:00
adobe_flashplayer_avm.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
adobe_flashplayer_flash10o.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
adobe_flashplayer_newfunction.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
adobe_flatedecode_predictor02.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
adobe_geticon.rb Add Adobe security bulletin references 2012-09-04 00:07:53 -05:00
adobe_jbig2decode.rb Add Adobe security bulletin references 2012-09-04 00:07:53 -05:00
adobe_media_newplayer.rb Add Adobe security bulletin references 2012-09-04 00:07:53 -05:00
adobe_shockwave_rcsl_corruption.rb Add Adobe security bulletin references 2012-09-04 00:07:53 -05:00
adobe_utilprintf.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
aim_goaway.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
amaya_bdo.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
aol_ampx_convertfile.rb Update CVE/OSVDB/Milw0rm references for browser modules 2012-06-28 00:26:20 -05:00
aol_icq_downloadagent.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
apple_itunes_playlist.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
apple_quicktime_marshaled_punk.rb 'cli' should be 'client' 2012-04-17 07:12:08 -05:00
apple_quicktime_rtsp.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
apple_quicktime_smil_debug.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
ask_shortformat.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
asus_net4switch_ipswcom.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
athocgov_completeinstallation.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
autodesk_idrop.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
aventail_epi_activex.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
awingsoft_web3d_bof.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
awingsoft_winds3d_sceneurl.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
baofeng_storm_onbeforevideodownload.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
barcode_ax49.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
blackice_downloadimagefileurl.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
c6_messenger_downloaderactivex.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
ca_brightstor_addcolumn.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
chilkat_crypt_writefile.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
cisco_anyconnect_exec.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
cisco_playerpt_setsource.rb Blah, removed the wrong ref. 2012-07-30 12:47:32 -05:00
cisco_playerpt_setsource_surl.rb juan author name updated 2012-08-06 18:59:16 +02:00
citrix_gateway_actx.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
clear_quest_cqole.rb Add Metasploit blogs as references, because they're useful. 2012-09-03 15:57:27 -05:00
communicrypt_mail_activex.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
creative_software_cachefolder.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
dell_webcam_crazytalk.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
dxstudio_player_exec.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
ea_checkrequirements.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ebook_flipviewer_fviewerloading.rb Fix more print_* 2012-04-25 15:01:50 -05:00
enjoysapgui_comp_download.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
enjoysapgui_preparetoposthtml.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
facebook_extractiptc.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
gom_openurl.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
greendam_url.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
hp_easy_printer_care_xmlcachemgr.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
hp_easy_printer_care_xmlsimpleaccessor.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
hp_loadrunner_addfile.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
hp_loadrunner_addfolder.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
hpmqc_progcolor.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
hyleos_chemviewx_activex.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ibm_tivoli_pme_activex_bof.rb Merge branch 'rapid7' into http-print-standardization 2012-04-18 08:51:42 -06:00
ibmegath_getxmlvalue.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ibmlotusdomino_dwa_uploadmodule.rb Update milw0rm references. 2012-06-28 14:27:12 -05:00
ie_createobject.rb Merge branch 'rapid7' into http-print-standardization 2012-04-18 08:51:42 -06:00
ie_execcommand_uaf.rb update to ie_execcommand_uaf's info to add ROP info 2012-09-19 14:10:02 -05:00
ie_iscomponentinstalled.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ie_unsafe_scripting.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
imgeviewer_tifmergemultifiles.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
intrust_annotatex_add.rb Merge branch 'jlee-r7-http-print-standardization' 2012-04-25 15:38:46 -05:00
java_basicservice_impl.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
java_codebase_trust.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
java_docbase_bof.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
java_mixer_sequencer.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
java_ws_arginject_altjvm.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
java_ws_vmargs.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
juniper_sslvpn_ive_setupdll.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
kazaa_altnet_heap.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
logitechvideocall_start.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
lpviewer_url.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
macrovision_downloadandexecute.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
macrovision_unsafe.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
mcafee_mcsubmgr_vsprintf.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
mcafee_mvt_exec.rb Update CVE/OSVDB/Milw0rm references for browser modules 2012-06-28 00:26:20 -05:00
mcafeevisualtrace_tracetarget.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
mirc_irc_url.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
mozilla_attribchildremoved.rb If the target isn't support, make sure we warn the user 2012-05-17 12:34:17 -05:00
mozilla_interleaved_write.rb Merge branch 'jlee-r7-http-print-standardization' 2012-04-25 15:38:46 -05:00
mozilla_mchannel.rb Un-standardize printing in browser modules 2012-04-11 00:26:25 -06:00
mozilla_nssvgvalue.rb Fix broken target (variable naming) 2012-05-17 11:37:49 -05:00
mozilla_nstreerange.rb Un-standardize printing in browser modules 2012-04-11 00:26:25 -06:00
mozilla_reduceright.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
ms03_020_ie_objecttype.rb Merge branch 'rapid7' into http-print-standardization 2012-04-18 08:51:42 -06:00
ms05_054_onload.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms06_001_wmf_setabortproc.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms06_013_createtextrange.rb Change unknown authors to "Unknown". 2012-05-26 15:23:09 -05:00
ms06_055_vml_method.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms06_057_webview_setslice.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms06_067_keyframe.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms06_071_xml_core.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms07_017_ani_loadimage_chunksize.rb Additional exploit fail_with() changes to remove raise calls 2012-06-19 19:43:41 -05:00
ms08_041_snapshotviewer.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
ms08_053_mediaencoder.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms08_070_visual_studio_msmask.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms08_078_xml_corruption.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms09_002_memory_corruption.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms09_043_owc_htmlurl.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms09_043_owc_msdso.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms09_072_style_object.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms10_002_aurora.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms10_002_ie_object.rb Whitespace, thanks msftidy.rb! 2012-05-31 18:18:27 -06:00
ms10_018_ie_behaviors.rb Un-standardize printing in browser modules 2012-04-11 00:26:25 -06:00
ms10_018_ie_tabular_activex.rb Change unknown authors to "Unknown". 2012-05-26 15:23:09 -05:00
ms10_022_ie_vbscript_winhlp32.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
ms10_026_avi_nsamplespersec.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms10_042_helpctr_xss_cmd_exec.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
ms10_046_shortcut_icon_dllloader.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
ms10_090_ie_css_clip.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ms11_003_ie_css_import.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
ms11_050_mshtml_cobjectelement.rb Un-standardize printing in browser modules 2012-04-11 00:26:25 -06:00
ms11_093_ole32.rb Change the title and add a Microsoft reference. 2012-06-10 14:45:15 -05:00
ms12_004_midi.rb Merge branch 'jlee-r7-http-print-standardization' 2012-04-25 15:38:46 -05:00
ms12_037_ie_colspan.rb juan author name updated 2012-08-06 18:59:16 +02:00
ms12_037_same_id.rb Add Metasploit blogs as references, because they're useful. 2012-09-03 15:57:27 -05:00
msvidctl_mpeg2.rb Fix possible "can't convert Fixnum into String" error 2012-04-30 13:49:53 -05:00
mswhale_checkforupdates.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
msxml_get_definition_code_exec.rb Add Metasploit blogs as references, because they're useful. 2012-09-03 15:57:27 -05:00
nctaudiofile2_setformatlikesample.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
nis2004_antispam.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
nis2004_get.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_callbackurl.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_datetime.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_executerequest.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_executerequest_dbg.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_getdriversettings.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_getdriversettings_2.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
novelliprint_target_frame.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
oracle_autovue_setmarkupmode.rb Add Metasploit blogs as references, because they're useful. 2012-09-03 15:57:27 -05:00
oracle_dc_submittoexpress.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
orbit_connecting.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
pcvue_func.rb Update CVE/OSVDB/Milw0rm references for browser modules 2012-06-28 00:26:20 -05:00
persits_xupload_traversal.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
real_arcade_installerdlg.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
realplayer_cdda_uri.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
realplayer_console.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
realplayer_import.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
realplayer_qcp.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
realplayer_smil.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
roxio_cineplayer.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
safari_xslt_output.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
samsung_neti_wiewer_backuptoavi_bof.rb Caps in title 2012-06-13 14:19:04 -05:00
sapgui_saveviewtosessionfile.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
softartisans_getdrivename.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
sonicwall_addrouteentry.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
symantec_altirisdeployment_downloadandinstall.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
symantec_altirisdeployment_runcmd.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
symantec_appstream_unsafe.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
symantec_backupexec_pvcalendar.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
symantec_consoleutilities_browseandsavefile.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
systemrequirementslab_unsafe.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
teechart_pro.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
tom_sawyer_tsgetx71ex552.rb Use of make_nops 2012-06-08 19:20:58 +02:00
trendmicro_extsetowner.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
trendmicro_officescan.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
tumbleweed_filetransfer.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
ubisoft_uplay_cmd_exec.rb Blah, OSVDB ref shouldn't be a link 2012-08-06 11:57:59 -05:00
ultramjcam_openfiledig_bof.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
ultraoffice_httpupload.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
verypdf_pdfview.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
viscom_movieplayer_drawtext.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
vlc_amv.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
vlc_mms_bof.rb Fixes #362 by changing the exitfunction arguments to be the correct type 2012-05-07 02:41:08 -05:00
webdav_dll_hijacker.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
webex_ucf_newobject.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
winamp_playlist_unc.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
winamp_ultravox.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
windvd7_applicationtype.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
winzip_fileview.rb Merge branch 'rapid7' into http-print-standardization 2012-04-18 08:51:42 -06:00
wmi_admintools.rb This mega-diff adds better error classification to existing modules 2012-06-19 12:59:15 -05:00
xmplay_asx.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
yahoomessenger_fvcom.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
yahoomessenger_server.rb Remove spurious cli.peerhost in output 2012-04-20 13:31:42 -06:00
zenturiprogramchecker_unsafe.rb Take into account an integer-normalized datastore 2012-06-24 23:00:02 -05:00
zenworks_helplauncher_exec.rb juan author name updated 2012-08-06 18:59:16 +02:00