vendor:
RDS.DataStore
by:
redsand@blacksecurity.org
9,3
CVSS
HIGH
Data Execution
94
CWE
Product Name: RDS.DataStore
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2006-0003, MS06-014
CPE: N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
April 2006
[BL4CK] – MS06-014
This exploit is a bit out-dated but works very well. It is used to execute a malicious code on the vulnerable system. It uses an XML AJAX request to download a file from a URL and then executes it using the ShellExecute function.
Mitigation:
Disable VBScript, use a web application firewall, and apply the latest security patches.