vendor:
Domain Quester Pro
by:
boku
7.5
CVSS
HIGH
Stack Overflow (SEH)
121
CWE
Product Name: Domain Quester Pro
Affected Version From: Version 6.02
Affected Version To: Version 6.02
Patch Exists: NO
Related CWE:
CPE: a:internet-soft:domain_quester_pro:6.02
Platforms Tested: Microsoft Windows 7 Enterprise
2019
Domain Quester Pro 6.02 – Stack Overflow (SEH)
The exploit triggers a stack overflow vulnerability in Domain Quester Pro 6.02. By pasting a specially crafted payload into the 'Domain Name Keywords' textbox, an attacker can cause the program to freeze and a bind shell to be opened on TCP port 9999, allowing for remote code execution.
Mitigation:
Update to a patched version of Domain Quester Pro.