forked from offensive-security/exploitdb
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
1 changes to exploits/shellcodes Odoo 12.0.20190101 - 'nssm.exe' Unquoted Service Path
- Loading branch information
Offensive Security
committed
May 12, 2021
1 parent
599b380
commit c3ea8f9
Showing
2 changed files
with
25 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
# Exploit Title: Odoo 12.0.20190101 - 'nssm.exe' Unquoted Service Path | ||
# Exploit Author: 1F98D | ||
# Vendor Homepage: https://www.odoo.com/ | ||
# Software Link: https://nightly.odoo.com/12.0/nightly/windows/odoo_12.0.20190101.exe | ||
# Tested Version: 12.0.20190101 | ||
# Tested on OS: Windows | ||
# Step to discover Unquoted Service Path: | ||
|
||
C:\> icacls "C:\Program Files (x86)\Odoo 12.0\nssm" | ||
|
||
C:\Program Files (x86)\Odoo 12.0\nssm pc-1\user-1:(OI)(CI)(M) | ||
NT SERVICE\TrustedInstaller:(I)(F) | ||
NT SERVICE\TrustedInstaller:(I)(CI)(IO)(F) | ||
NT AUTHORITY\SYSTEM:(I)(F) | ||
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(IO)(F) | ||
BUILTIN\Administrators:(I)(F) | ||
BUILTIN\Administrators:(I)(OI)(CI)(IO)(F) | ||
BUILTIN\Users:(I)(RX) | ||
BUILTIN\Users:(I)(OI)(CI)(IO)(GR,GE) | ||
CREATOR OWNER:(I)(OI)(CI)(IO)(F) | ||
APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX) | ||
APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE) | ||
APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(RX) | ||
APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters