vendor:
HTML Creator & Sender
by:
Dr_IDE
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: HTML Creator & Sender
Affected Version From: 2.3 Build 697
Affected Version To: 2.3 Build 697
Patch Exists: Yes
Related CWE: N/A
CPE: a:html-email:html_creator_and_sender
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2009
HTML Creator & Sender <= v2.3 Build 697 Local Buffer Overflow Exploit (SEH)
This exploit is based on a local buffer overflow vulnerability in HTML Creator & Sender version 2.3 Build 697. The vulnerability is triggered when a maliciously crafted file is opened in the application. This can lead to arbitrary code execution in the context of the application.
Mitigation:
Update to the latest version of HTML Creator & Sender.