vendor:
iSmartViewPro
by:
Gionathan 'John' Reale
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: iSmartViewPro
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: N/A
CPE: a:securimport:ismartviewpro:1.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32bit
2018
iSmartViewPro 1.5 – ‘SavePath for ScreenShots’ Buffer Overflow (SEH)
iSmartViewPro 1.5 is vulnerable to a buffer overflow vulnerability when a maliciously crafted input is supplied to the 'Save Path for Snapshot and Record file' field. This can be exploited to execute arbitrary code by overwriting the SEH handler with a malicious payload.
Mitigation:
Upgrade to the latest version of iSmartViewPro 1.5