2007/05/04

-----------------------------------------------------------------------------
 Office Viewer (OA.ocx v. 3.2.0.5) multiple methods Denial of Service
 url: http://www.officeocx.com/
 price: from �77.95 (update to last version) to �1,558.95 (Royalty)

 author: shinnai
 mail: shinnai[at]autistici[dot]org
 site: http://shinnai.altervista.org

 Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7
 all software that use this ocx are vulnerable to these exploits.
 Theese methods are vulnerable too:

 DoOleCommand
 FTPDownloadFile
 FTPUploadFile
 HttpUploadFile
 Save
 SaveWebFile
-----------------------------------------------------------------------------









# milw0rm.com [2007-05-04]