vendor:
Easy RM to MP3
by:
Oh Yaw Theng
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy RM to MP3
Affected Version From: 2.7.3.700
Affected Version To: 2.7.3.700
Patch Exists: NO
Related CWE: N/A
CPE: 2.7.3.700
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP 1
2010
Easy RM to MP3 2.7.3.700 Local Buffer Overflow (.m3u , .pls , .smi , .wpl , .wax , .wvx , .ram)
This exploit works for all the file extensions mentioned above. The user just needs to change the file extension below with the extension mentioned above. 35032 bytes are needed before overwriting EIP register. JMP ESP in SHELL32.DLL is used to bind a shell at TCP Port 5555 (Telnet to this port after exploiting target).
Mitigation:
Ensure that all user input is validated and sanitized before being used in any application.