vendor:
Easy Chat Server
by:
LSO
N/A
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy Chat Server
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2004-2466
CPE: a:efs_software:easy_chat_server
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/http/efs_easychatserver_username, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=71859, https://www.infosecmatter.com/nessus-plugin-library/?id=71861
Platforms Tested: Windows
2007
EFS Easy Chat Server Authentication Request Handling Buffer Overflow
This module exploits a stack buffer overflow in EFS Software Easy Chat Server. By sending a overly long authentication request, an attacker may be able to execute arbitrary code. The offset to SEH is influenced by the installation path of the program. The path, which defaults to "C:Program FilesEasy Chat Server", is concatenated with "users" and the string passed as the username HTTP parameter."
Mitigation:
Unknown