CVE-2014-100015
SolidWorks Workgroup PDM 2014 - Unauthenticated Path Traversal and Arbitrary File Write via File Upload
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2014-100015.
PoCs published by Metasploit, Mohamed Shetta, including Metasploit module exploits/windows/misc/solidworks_workgroup_pdmwservice_file_write.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file write vulnerability in SolidWorks Workgroup PDM 2014 SP2 and prior. It achieves remote code execution by uploading a payload to the startup folder (Windows Vista onwards) or via WMI execution (Windows XP).
Description
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (dot dot) in the filename in a file upload.
Exploits (3)
This Metasploit module exploits an arbitrary file write vulnerability in SolidWorks Workgroup PDM 2014 SP2 and prior. It achieves remote code execution by uploading a payload to the startup folder (Windows Vista onwards) or via WMI execution (Windows XP).
This exploit targets SolidWorks Workgroup PDM 2014 SP2, allowing arbitrary file writes via a network socket connection to port 30000. It constructs a malicious payload with an opcode, filename, and data to write, demonstrating the vulnerability.
This Metasploit module exploits an arbitrary file write vulnerability in SolidWorks Workgroup PDM 2014 SP2 and prior, allowing remote code execution by uploading a payload to the startup folder or via WMI on Windows XP.