Sploitus

Exploit for Windows MDAC RDS.Dataspace ActiveX control vulnerability

saint · 2007-07-16

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:191E4D213693C8769F03A620EE4E529A
Added: 07/16/2007  
CVE: [CVE-2006-0003](<https://vulners.com/cve/CVE-2006-0003>)  
BID: [17462](<http://www.securityfocus.com/bid/17462>)  
OSVDB: [24517](<http://www.osvdb.org/24517>)  


### Background

[Microsoft Data Access Components (MDAC)](<http://support.microsoft.com/kb/842193/>) enable Universal Data Access in Windows applications deployed over a network. 

### Problem

A cross-zone scripting vulnerability in the RDS.Dataspace ActiveX control in MDAC allows command execution when a user loads a specially crafted web page. 

### Resolution

Apply the update referenced in [Microsoft Security Bulletin 06-014](<http://www.microsoft.com/technet/security/bulletin/MS06-014.mspx>). 

### References

<http://www.kb.cert.org/vuls/id/234812>  


### Limitations

On Windows 2000, MDAC must be installed. 

### Platforms

Windows