vendor:
Dup Scout Enterprise
by:
@0rbz_
9.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Dup Scout Enterprise
Affected Version From: 10.0.18
Affected Version To: 10.0.18
Patch Exists: YES
Related CWE: N/A
CPE: a:dupscout:dup_scout_enterprise:10.0.18
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro (x64)
2018
Dup Scout Enterprise 10.0.18 – ‘online_registration’ Remote Buffer Overflow
Dup Scout Enterprise 10.0.18 is vulnerable to a remote buffer overflow vulnerability. The vulnerability exists in the 'online_registration' web service, which is enabled by default. An attacker can exploit this vulnerability by sending a specially crafted POST request with an overly long string in the 'Content-Length' header. This will cause a buffer overflow, allowing the attacker to execute arbitrary code on the target system.
Mitigation:
Disable the 'online_registration' web service, or apply the latest security patches.