vendor:
Chasys Media Player
by:
Encrypt3d.M!nd
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Chasys Media Player
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Unknown
Chasys Media Player 1.1 (.pls) Stack Overflow Exploit
This exploit is for Chasys Media Player version 1.1. It takes advantage of a stack overflow vulnerability in the program's handling of .pls files. By creating a specially crafted .pls file, an attacker can execute arbitrary code on the target system. The exploit includes a shellcode payload that launches a bind shell on port 666.
Mitigation:
Apply patches or update to a newer version of Chasys Media Player.