vendor:
HTML Email Creator
by:
dun
7,6
CVSS
HIGH
Local SEH Overwrite Exploit
119
CWE
Product Name: HTML Email Creator
Affected Version From: 2.1 build 668
Affected Version To: 2.1 build 668
Patch Exists: YES
Related CWE: N/A
CPE: a:html-email:html_email_creator
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 and Windows XP
2009
HTML Email Creator <= 2.1 build 668 Local SEH Overwrite Exploit
This exploit is for HTML Email Creator <= 2.1 build 668. It is a Local SEH Overwrite Exploit which is triggered by using a malicious <img> tag. The exploit code contains a NOP sled followed by a short jump (jmp 11) and a pop-pop-ret address. The exploit code also contains a shellcode which is used to execute a calculator program. The exploit has been tested on Windows XP SP2 with installed PC TOOLS Spyware Doctor and Windows XP without any upgrades.
Mitigation:
The vendor has released a patch to address this vulnerability.