header-logo
Suggest Exploit
vendor:
Sysax Multi Server
by:
Craig Freyman
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sysax Multi Server
Affected Version From: 5.50
Affected Version To: 5.51
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 32bit and Server 2003 SP2 32bit(No DEP)
2012

Sysax Multi Server 5.50 Create Folder Remote Code Exec BoF (MSF Module)

This module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.

Mitigation:

Upgrade to Sysax Multi Server 5.52 or later
Source

Exploit-DB raw data: