global security disclosure
Showing 1 - 1 of 1 RSS Feed

Files

Persits XUpload ActiveX MakeHttpRequest Directory Traversal
Posted Dec 31, 2009
Authored by jduck | Site metasploit.com

This Metasploit module exploits a directory traversal in Persits Software Inc's XUpload ActiveX control(version 3.0.0.3) that's included in HP LoadRunner 9.5. By passing a string containing "..\\\\" sequences to the MakeHttpRequest method, an attacker is able to write arbitrary files to arbitrary locations on disk. Code execution occurs by writing to the All Users Startup Programs directory. You may want to combine this module with the use of multi/handler since a user would have to log for the payload to execute.

tags | exploit, arbitrary, code execution, activex
advisories | CVE-2009-3693
MD5 | 21253126f433fcd26e510a6f0bb90732
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close