10
CVSSv2

CVE-2008-6935

Published: 11/08/2009 Updated: 11/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Argument injection vulnerability in Exodus 0.10 allows remote malicious users to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.

Vulnerable Product Search on Vulmon Subscribe to Product

joe fuhrman exodus 0.10

Exploits

-------------------------------------------------------------------------------- Exodus v010 uri handler arbitrary parameter injection by Nine:Situations:Group::strawdog tested against IE8b/xpsp3 may not work against non-English systems because of an installation bug -------------------------------------------------------------------------------- ...
<!-- Exodus v010 remote code execution exploit by Nine:Situations:Group::strawdog This uses the "-l" argument to overwrite a file inside Microsoft Help and Support Center folders (oh rgod) Firstly run netcat in listen mode to drop the vbscript shell run this script: @echo off rem dropshcmd echo ^<SCRIPT LANGUAGE="VBScript"^> > t ...