CVE-2010-3964
published 2010-12-16CVE-2010-3964: Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document…
high7.5CVSS 3.1
AVNACLAuNCPIPAP
EXPLOIT
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | sharepoint_server | — | — |
No detection rules found.
Exploit-DB
Microsoft Office SharePoint Server 2007 - Remote Code Execution (MS10-104) (Metasploit)
exploitdb·2012-07-31
CVE-2010-3964 Microsoft Office SharePoint Server 2007 - Remote Code Execution (MS10-104) (Metasploit)
Microsoft Office SharePoint Server 2007 - Remote Code Execution (MS10-104) (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'Microsoft Office SharePoint Server 2007 Remote Code Execution',
'Description' => %q{
This module exploits a vulnerability found in SharePoint Server 2007 SP2. The
software contains a directory traversal, that allows a remote attacker to write
arbitrary files to the filesystem, sending a specially crafted SOAP ConvertFile
request to the Office Document Conversions Launcher Service, which results in code
execution under the cont
Metasploit
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
metasploit
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
This module exploits a vulnerability found in SharePoint Server 2007 SP2. The software contains a directory traversal, that allows a remote attacker to write arbitrary files to the filesystem, sending a specially crafted SOAP ConvertFile request to the Office Document Conversions Launcher Service, which results in code execution under the context of 'SYSTEM'. The module uses the Windows Management Instrumentation service to execute an arbitrary payload on vulnerable installations of SharePoint on Windows 2003 Servers. It has been successfully tested on Office SharePoint Server 2007 SP2 over Windows 2003 SP2.
http://osvdb.org/69817http://secunia.com/advisories/42631http://www.securityfocus.com/bid/45264http://www.securitytracker.com/id?1024886http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlhttp://www.vupen.com/english/advisories/2010/3226http://www.zerodayinitiative.com/advisories/ZDI-10-287/https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737http://osvdb.org/69817http://secunia.com/advisories/42631http://www.securityfocus.com/bid/45264http://www.securitytracker.com/id?1024886http://www.us-cert.gov/cas/techalerts/TA10-348A.htmlhttp://www.vupen.com/english/advisories/2010/3226http://www.zerodayinitiative.com/advisories/ZDI-10-287/https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737
2010-12-16
Published