vendor:
PdvrAtl Module
by:
rgod
9.3
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: PdvrAtl Module
Affected Version From: 1.0.1.25
Affected Version To: 1.0.1.25
Patch Exists: Yes
Related CWE: N/A
CPE: a:nuvico:pdvratl_module:1.0.1.25
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IE7/XP SP2
2009
NUVICO DVR NVDV4 / PdvrAtl Module (PdvrAtl.DLL 1.0.1.25) remote heap overflow exploit (IE7/XP SP2)
A heap overflow vulnerability exists in NUVICO DVR NVDV4 / PdvrAtl Module (PdvrAtl.DLL 1.0.1.25) when processing a specially crafted web page. An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the affected application. A demonstration of the vulnerability can be found at http://www.2mcctv.com/2mdemo.php and the codebase can be found at http://www.dvrstation.com/pdvratl.php?vendor=0.
Mitigation:
Upgrade to the latest version of NUVICO DVR NVDV4 / PdvrAtl Module (PdvrAtl.DLL 1.0.1.25) or apply the appropriate patch.