vendor:
GetGo Download Manager
by:
Aloyce J. Makalanga
9,8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: GetGo Download Manager
Affected Version From: 5.3.0.2712
Affected Version To: 5.3.0.2712
Patch Exists: NO
Related CWE: CVE-2017-17849
CPE: 2.3:a:getgo_software:getgo_download_manager:5.3.0.2712
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 32 bits
2017
Buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response. To exploit this vulnerability, an attacker needs to issue a malicious-crafted payload in the HTTP Response Header. A successful attack could result in code execution on the victim computer.
Mitigation:
No solution as of yet.