MondoSoft's MondoSearch File Creation Vulnerability
A vulnerability in Mondosoft MondoSearch for Windows can result in the execution of arbitrary code on the vulnerable computer.
September 25, 2003
Reported September 24, 2003 by Jens H. Christensen.
VERSIONS AFFECTED
Mondosoft MondoSearch 5.1, 5.0, and 4.4 for Windows
DESCRIPTION
A vulnerability in Mondosoft MondoSearch for Windows can result in the execution of arbitrary code on the vulnerable computer. One of the default installation files, msmsetup.exe, contains a vulnerability that lets malicious users create files with user-specified content on the Web server or anywhere that the executing user (typically IUSR_xxx) has write access. For details about this vulnerability, see the discoverer's web site.
VENDOR RESPONSE
Mondosoft has released a patch for this vulnerability.
CREDIT
Discovered byJens H. Christensen.
About the Author
You May Also Like