vendor:
Durian Web Application Server
by:
rgod
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: Durian Web Application Server
Affected Version From: 03.02
Affected Version To: 03.02
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
Durian Web Application Server 3.02 freeware for Win32 buffer overflow execute command exploit
This is a buffer overflow exploit for Durian Web Application Server version 3.02. It allows an attacker to execute arbitrary commands on the target system. The exploit overflows the buffer with a specially crafted payload, including a shellcode that executes the 'notepad' command.
Mitigation:
Apply the vendor's patch or upgrade to a non-vulnerable version of the software.