CVE-2001-0148
Windows Media Player 7 - Remote Code Execution via JavaScript URL in ActiveX Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0148. PoCs published by Georgi Guninski.
AI-analyzed exploit summary This exploit leverages a vulnerability in Windows Media Player 7 ActiveX control to execute arbitrary JavaScript in the context of an already open frame, bypassing security restrictions. It demonstrates reading local files and potentially executing arbitrary programs via a crafted HTML page.
Description
The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.
Exploits (1)
This exploit leverages a vulnerability in Windows Media Player 7 ActiveX control to execute arbitrary JavaScript in the context of an already open frame, bypassing security restrictions. It demonstrates reading local files and potentially executing arbitrary programs via a crafted HTML page.