vendor:
FlashGet
by:
SkOd
7.5
CVSS
HIGH
SEH STACK Overflow
Not provided
CWE
Product Name: FlashGet
Affected Version From: FlashGet 1.9.0.1012
Affected Version To: FlashGet 1.9.0.1012
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows XP SP1 Hebrew
Not provided
FlashGet FTP PWD Response SEH STACK Overflow Exploit
This exploit targets a vulnerability in FlashGet 1.9.0.1012 (FTP PWD Response) where a stack overflow can occur. The exploit code is written in Perl and uses a specially crafted payload to trigger the vulnerability. The exploit has been tested on Windows XP SP1 Hebrew. The victim needs to be linked to a file on a FTP server to trigger the exploit. The exploit includes a shellcode that executes arbitrary commands on the target system.
Mitigation:
Unknown