vendor:
ZipScan
by:
Lincoln & corelanc0d3r
7,8
CVSS
HIGH
SEH
119
CWE
Product Name: ZipScan
Affected Version From: 2.2c
Affected Version To: 2.2c
Patch Exists: YES
Related CWE: N/A
CPE: zipscan
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
ZipScan 2.2c (.zip) SEH Exploit
This exploit is for ZipScan 2.2c (.zip) SEH vulnerability. It creates an evil zip file with a payload of 5000 bytes. The payload contains a POP POP RETN sequence followed by a NOP sled and a shellcode. The shellcode is used to execute malicious code on the target system.
Mitigation:
Upgrade to the latest version of ZipScan 2.2c (.zip)