retrogod.altervista.org
http://retrogod.altervista.org/9sg_ibm_uri.html CVE-2009-3518
IBM Installation Manager 1.3.0 - 'iim://' URI handler
Record summary
CVE-2009-3518 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM Installation Manager 1.3.0 - 'iim://' URI handlerExploitDB exploitby bruiserNot analyzed1 file
References
436906Third-party advisory
http://secunia.com/advisories/36906 ADV-2009-2792vdb entry
http://www.vupen.com/english/advisories/2009/2792 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-3518