CVE-2008-6935
Exodus 0.10 - Argument Injection via Encoded Spaces in im:// URI
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6935. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit leverages a vulnerability in Exodus v0.10 to achieve remote code execution by overwriting a file in the Microsoft Help and Support Center folder via the '-l' argument. The exploit uses a crafted HTML file with malicious links to trigger the vulnerability and execute arbitrary VBScript code.
Description
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.
Exploits (2)
This exploit leverages a vulnerability in Exodus v0.10 to achieve remote code execution by overwriting a file in the Microsoft Help and Support Center folder via the '-l' argument. The exploit uses a crafted HTML file with malicious links to trigger the vulnerability and execute arbitrary VBScript code.
This exploit leverages a URI handler vulnerability in Exodus v0.10 to inject arbitrary command-line parameters, allowing file overwrites and potential DoS via malformed URIs. The PoC demonstrates how the 'im://' URI scheme can be abused to manipulate the application's behavior.