vendor:
VX Search Enterprise
by:
Greg Priest
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: VX Search Enterprise
Affected Version From: VX Search Enterprise v9.5.12
Affected Version To: VX Search Enterprise v9.5.12
Patch Exists: YES
Related CWE: N/A
CPE: a:vxsearch:vx_search_enterprise:9.5.12
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows7 x64 HUN/ENG Professional
2017
VX Search Enterprise v9.5.12 email verify exploit
A buffer overflow vulnerability exists in VX Search Enterprise v9.5.12 when sending an overly long string to the email verify function. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. The vulnerability is due to a boundary error when handling user-supplied input. A remote attacker can send a specially crafted request to the vulnerable application and execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of VX Search Enterprise v9.5.12