vendor:
by:
Inphex
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name:
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP
Unknown
Windows Command Shell Bind TCP Inline
This exploit allows an attacker to execute arbitrary commands on a Windows XP system by exploiting a vulnerability in the mSQL extension. The attacker can bind a TCP shell to a specific port and gain remote access to the target system.
Mitigation:
To mitigate this vulnerability, ensure that the mSQL extension is disabled or removed from the system if not required.