SAP MaxDB 'cons.exe' Remote Command Injection Vulnerability

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The following exploit example is available:

exec_sdbinfo && echo dir c:\ | cmd.exe

The following exploit code is available:


 

Privacy Statement
Copyright 2010, SecurityFocus