header-logo
Suggest Exploit
vendor:
ASP Ticker
by:
ZoRLu
9.3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ASP Ticker
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: N/A
CPE: a:merlix:aspticker:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

ASP Ticker 1.0 DD Remote Vuln.

A vulnerability in ASP Ticker 1.0 allows remote attackers to execute arbitrary code by uploading a malicious .mdb file to the news.mdb directory. This can be done by sending a POST request to the news.mdb directory with a malicious .mdb file as the payload.

Mitigation:

Upgrade to the latest version of ASP Ticker 1.0 or apply the patch provided by the vendor.
Source

Exploit-DB raw data:

[~] ASPTicker 1.0 DD Remote Vuln.
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu   msn: trt-turk@hotmail.com
[~]
[~] Home: www.z0rlu.blogspot.com
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~] -----------------------------------------------------------


exp for demo: ( DD )

http://demo.merlix.com/ticker/news.mdb

[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke 
[~]
[~] yildirimordulari.org  &  darkc0de.com
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2008-12-05]