vendor:
by:
Felipe Winsnes
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name:
Affected Version From: 3.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 (x86)
2020
Calavera UpLoader 3.5 – ‘FTP Logi’ Denial of Service (PoC + SEH Overwrite)
This exploit demonstrates a denial of service vulnerability in Calavera UpLoader 3.5. The vulnerability is triggered when specific content is pasted into the 'FTP Address', 'Username', and 'Password' parameters in the application's settings. The exploit creates a file named 'poc.txt' with a specific payload, causing the application to crash. Additionally, the exploit overwrites SEH values, causing continued crashes on subsequent application launches until the 'uploadpref.dat' file is deleted. If only the 'Password' parameter is pasted with the exploit content, the application crashes once without creating 'uploadpref.dat'.
Mitigation:
To mitigate this vulnerability, it is recommended to update Calavera UpLoader to a patched version or apply any available security updates. Alternatively, users can refrain from pasting malicious content into the 'FTP Address', 'Username', and 'Password' parameters in the application's settings.