vendor:
dBpowerAMP Audio Player
by:
SimO-s0fT
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: dBpowerAMP Audio Player
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 and Windows XP SP1
2008
simo36.c
dBpowerAMP Audio Player local buffer overflow exploit. This exploit was tested on Windows XP SP2 and Windows XP SP1. It allows an attacker to execute arbitrary code on the vulnerable system by creating a malicious .pls file and opening it with dBpowerAMP. The exploit can be used to execute calc.exe or bindshell LPORT=7777.
Mitigation:
Update to the latest version of dBpowerAMP Audio Player.