vendor:
Amaya Web Editor
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
SEH Overwrite
121
CWE
Product Name: Amaya Web Editor
Affected Version From: Amaya Web Editor version 11
Affected Version To: Amaya Web Editor version 11
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Microsoft Windows XP Professional SP2
2009
Amaya Web Editor 11 Remote SEH Overwrite Exploit
This exploit targets Amaya Web Editor version 11 and allows remote attackers to overwrite the Structured Exception Handler (SEH) chain, leading to arbitrary code execution. It takes advantage of a vulnerability in the handling of the 'dir' parameter in the HTML code.
Mitigation:
Update Amaya Web Editor to a version that has patched this vulnerability.