header-logo
Suggest Exploit
vendor:
GetGo Download Manager
by:
Aloyce J. Makalanga
9,8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: GetGo Download Manager
Affected Version From: 5.3.0.2712
Affected Version To: 5.3.0.2712
Patch Exists: NO
Related CWE: CVE-2017-17849
CPE: 2.3:a:getgo_software:getgo_download_manager:5.3.0.2712
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 32 bits
2017

Buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712

A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response. To exploit this vulnerability, an attacker needs to issue a malicious-crafted payload in the HTTP Response Header. A successful attack could result in code execution on the victim computer.

Mitigation:

No solution as of yet.
Source

Exploit-DB raw data: