vendor:
AlleyCode HTML Editor
by:
PCWorld Magazine
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: AlleyCode HTML Editor
Affected Version From: 2.21
Affected Version To: 2.21
Patch Exists: YES
Related CWE: N/A
CPE: a:alleycode:alleycode_html_editor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
AlleyCode HTML Editor Vulnerability
AlleyCode HTML Editor is vulnerable to a buffer overflow vulnerability when a specially crafted HTML file is opened and the Optimizer tool is used. This can lead to arbitrary code execution. The vulnerability is caused by the lack of proper validation of user-supplied input when processing the HTML file.
Mitigation:
Upgrade to the latest version of AlleyCode HTML Editor.