CORE IMPACT v9 - Exploits Update (Mon Nov 09 2009)
IBM Installation Manager URI Handler Argument Injection Exploit
Exploits/Client Side [Windows]
Mon Nov 09 2009
This module runs a web server waiting for vulnerable clients to connect to it. When the client connects, it will try to install an agent by instantiating the "iim" uri handler with a malicious DLL(impact.dll) as parameter.
Exploits Vulnerabiltiy: CVE-2009-3518











