vendor:
libxml
by:
infamous42md
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: libxml
Affected Version From: 2.6.12
Affected Version To: 2.6.12
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
libxml 2.6.12 nanoftp bof POC
This POC exploits a buffer overflow vulnerability in the libxml library version 2.6.12. It takes advantage of the xmlNanoFTPScanURL function to execute arbitrary code. The POC provides a shellcode that opens a shell on the target system. The vulnerability allows an attacker to execute remote code on the target system.
Mitigation:
Update to a patched version of the libxml library.