CVE-2009-0102
published 2009-12-09CVE-2009-0102: Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote…
PriorityP353critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
23.50%
97.5th percentile
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_project | — | — |
| microsoft | project_portfolio_server | — | — |
| microsoft | project_server | — | — |
| microsoft | project_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UPDATE SET SQL Injection Attempt
suricata·2010-07-30
CVE-2009-2734 ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UPDATE SET SQL Injection Attempt
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UPDATE SET SQL Injection Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UPDATE SET SQL Injection Attempt"; flow:established,to_server; http.uri; content:"/dispatch.php?atknodetype=reports.weekreport"; nocase; content:"userid="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; pcre:"/UPDATE.+SET/i"; reference:url,securitytracker.com/alerts/2009/Oct/1023017.html; reference:url,www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt; reference:url,www.securityfocus.com/bid/36660/info; reference:cve,2009-2734; classtype:web-application-attack; sid:2010135; rev:6; metadata:affected_product Web_Server_Applications, attack_target Web_Serv
Suricata
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UNION SELECT SQL Injection Attempt
suricata·2010-07-30
CVE-2009-2734 ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UNION SELECT SQL Injection Attempt
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UNION SELECT SQL Injection Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable UNION SELECT SQL Injection Attempt"; flow:established,to_server; http.uri; content:"/dispatch.php?atknodetype=reports.weekreport"; nocase; content:"userid="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:url,securitytracker.com/alerts/2009/Oct/1023017.html; reference:url,www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt; reference:url,www.securityfocus.com/bid/36660/info; reference:cve,2009-2734; classtype:web-application-attack; sid:2010131; rev:7; metadata:affected_product Web_Server_Applications, attack_target Web_Server, c
Suricata
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable DELETE FROM SQL Injection Attempt
suricata·2010-07-30
CVE-2009-2734 ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable DELETE FROM SQL Injection Attempt
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable DELETE FROM SQL Injection Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable DELETE FROM SQL Injection Attempt"; flow:established,to_server; http.uri; content:"/dispatch.php?atknodetype=reports.weekreport"; fast_pattern; nocase; content:"userid="; nocase; distance:0; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:url,securitytracker.com/alerts/2009/Oct/1023017.html; reference:url,www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt; reference:url,www.securityfocus.com/bid/36660/info; reference:cve,2009-2734; classtype:web-application-attack; sid:2010134; rev:8; metadata:affected_product Web_Server_Applications, atta
Suricata
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable SELECT FROM SQL Injection Attempt
suricata·2010-07-30
CVE-2009-2734 ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable SELECT FROM SQL Injection Attempt
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable SELECT FROM SQL Injection Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable SELECT FROM SQL Injection Attempt"; flow:established,to_server; http.uri; content:"/dispatch.php?atknodetype=reports.weekreport"; nocase; content:"userid="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; pcre:"/SELECT.+FROM/i"; reference:url,securitytracker.com/alerts/2009/Oct/1023017.html; reference:url,www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt; reference:url,www.securityfocus.com/bid/36660/info; reference:cve,2009-2734; classtype:web-application-attack; sid:2010132; rev:6; metadata:affected_product Web_Server_Applications, attack_target Web_
Suricata
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable INSERT INTO SQL Injection Attempt
suricata·2010-07-30
CVE-2009-2734 ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable INSERT INTO SQL Injection Attempt
ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable INSERT INTO SQL Injection Attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Achievo userid= Variable INSERT INTO SQL Injection Attempt"; flow:established,to_server; http.uri; content:"/dispatch.php?atknodetype=reports.weekreport"; fast_pattern; nocase; content:"userid="; nocase; distance:0; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:url,securitytracker.com/alerts/2009/Oct/1023017.html; reference:url,www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt; reference:url,www.securityfocus.com/bid/36660/info; reference:cve,2009-2734; classtype:web-application-attack; sid:2010133; rev:8; metadata:affected_product Web_Server_Applications, atta
No writeups or analysis indexed.
http://www.us-cert.gov/cas/techalerts/TA09-342A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-074https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6298http://www.us-cert.gov/cas/techalerts/TA09-342A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-074https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6298
2009-12-09
Published