vendor:
Sambar Server
by:
hdm, Andrew Griffiths, patrick
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sambar Server
Affected Version From: Sambar 6
Affected Version To: Sambar 6
Patch Exists: NO
Related CWE: CVE-2004-2086
CPE: a:sambar:sambar_server:6
Platforms Tested: Windows
2004
Sambar 6 Search Results Buffer Overflow
This module exploits a buffer overflow found in the /search/results.stm application that comes with Sambar 6. This code is a direct port of Andrew Griffiths's SMUDGE exploit, the only changes made were to the nops and payload. This exploit causes the service to die, whether you provided the correct target or not.
Mitigation:
Apply the latest patches provided by the vendor.