vendor:
File Sharing Wizard
by:
x00pwn
9.8
CVSS
CRITICAL
SEH overflow
119
CWE
Product Name: File Sharing Wizard
Affected Version From: 1.5.0
Affected Version To: 1.5.0
Patch Exists: YES
Related CWE: CVE-2019-16724
CPE: a:file_sharing_wizard:file_sharing_wizard:1.5.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2019
File sharing wizard ‘post’ remote SEH overflow
A SEH overflow vulnerability exists in File Sharing Wizard 1.5.0, which could allow an attacker to execute arbitrary code on the target system. The vulnerability is due to a lack of proper validation of user-supplied input when handling a 'POST' request. An attacker can exploit this vulnerability by sending a specially crafted 'POST' request to the vulnerable application. This may allow the attacker to execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of File Sharing Wizard.