MondoSoft's MondoSearch File Creation Vulnerability

A vulnerability in Mondosoft MondoSearch for Windows can result in the execution of arbitrary code on the vulnerable computer.

Ken Pfeil

September 25, 2003

1 Min Read
ITPro Today logo

Reported September 24, 2003 by Jens H. Christensen.

 

 

VERSIONS AFFECTED

 

Mondosoft MondoSearch 5.1, 5.0, and 4.4 for Windows

 

DESCRIPTION

 

A vulnerability in Mondosoft MondoSearch for Windows can result in the execution of arbitrary code on the vulnerable computer. One of the default installation files, msmsetup.exe, contains a vulnerability that lets malicious users create files with user-specified content on the Web server or anywhere that the executing user (typically IUSR_xxx) has write access. For details about this vulnerability, see the discoverer's web site.

 

VENDOR RESPONSE

 

Mondosoft has released a patch for this vulnerability.

 

CREDIT          
Discovered byJens H. Christensen.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like