vendor:
Syslog Server
by:
KF
7,5
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: Syslog Server
Affected Version From: G2SRv4.0.36.exe
Affected Version To: G2SRv4.0.36.exe
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP1
2006
Exploit for Syslog Server by eiQnetworks
This exploit overwrites the SEH on XP SP1. It just needs good shellcode. perhaps a reverse style jmp instead of a forward jump. This would eliminate the need for 2 stages of shellcode.
Mitigation:
Disable the syslog service on port 12345