vendor:
SharePoint Server 2007
by:
Oleksandr Mirosh, James Burton, juan
N/A
CVSS
N/A
Directory Traversal
22
CWE
Product Name: SharePoint Server 2007
Affected Version From: Microsoft Office SharePoint Server 2007 SP2
Affected Version To: Microsoft Windows Server 2003 SP2
Patch Exists: NO
Related CWE: CVE-2010-3964
CPE: a:microsoft:sharepoint_server_2007
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003
2010
Microsoft Office SharePoint Server 2007 Remote Code Execution
This module exploits a vulnerability found in SharePoint Server 2007 SP2. The software contains a directory traversal, that allows a remote attacker to write arbitrary files to the filesystem, sending a specially crafted SOAP ConvertFile request to the Office Document Conversions Launcher Service, which results in code execution under the context of 'SYSTEM'. The module uses uses the Windows Management Instrumentation service to execute an arbitrary payload on vulnerable installations of SharePoint on Windows 2003 Servers.
Mitigation:
No known mitigation or remediation for this vulnerability