2007/05/30
-------------------------------------------------------------------------------------------
Zenturi ProgramChecker ActiveX (sasatl.dll) Arbitrary file download/overwrite Exploit
url: http://www.programchecker.com/activeintro.aspx
author: shinnai
mail: shinnai[at]autistici[dot]org
site: http://shinnai.altervista.org
Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7
all software that use this ocx are vulnerable to this exploits.
Using the "DownloadFile" method, you can download everything you want on a pc. This
exploit just download a txt file on pc, I try to overwrite cmd.exe and it works.
-------------------------------------------------------------------------------------------