pre>

2007/05/30

------------------------------------------------------------------------------------------- Zenturi ProgramChecker ActiveX (sasatl.dll) Arbitrary file download/overwrite Exploit url: http://www.programchecker.com/activeintro.aspx author: shinnai mail: shinnai[at]autistici[dot]org site: http://shinnai.altervista.org Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7 all software that use this ocx are vulnerable to this exploits. Using the "DownloadFile" method, you can download everything you want on a pc. This exploit just download a txt file on pc, I try to overwrite cmd.exe and it works. -------------------------------------------------------------------------------------------