vendor:
XUpload Control
by:
e.b.
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XUpload Control
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 (fully patched) English, IE6 and IE7
Persits Software XUpload Control AddFolder BoF Exploit
This is a buffer overflow exploit for the Persits Software XUpload Control AddFolder() function. It allows an attacker to execute arbitrary code on a vulnerable system. The exploit contains two shellcode payloads, one for executing calc.exe and another for establishing a bind shell on port 4444.
Mitigation:
Apply the latest patches and updates from the vendor. Consider disabling or removing the vulnerable software if not needed.