vendor:
CCProxy
by:
KaGra
7.5
CVSS
HIGH
Remote Buffer Overflow
CWE
Product Name: CCProxy
Affected Version From: 6.2
Affected Version To: 6.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
CCProxy 6.2 ping Remote Buffer Overflow Exploit
Based on Ruder's discovery, this exploit allows an attacker to execute arbitrary code by sending a long parameter to the ping command in the telnet service of CCProxy server. The vulnerability is a stack-based overflow. The exploit uses a shellcode that binds to port 101 and connects back to the attacker using netcat. This exploit has been tested on Windows XP SP1 English.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. Users should update to the latest version of CCProxy.