vendor:
XUpload
by:
e.b.
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XUpload
Affected Version From: 3.0.0.4
Affected Version To: 3.0.0.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 (fully patched) with English language, IE6
Persits XUpload 3.0 AddFile() Buffer Overflow Exploit
This exploit targets a buffer overflow vulnerability in the AddFile() function of Persits XUpload 3.0. It allows an attacker to execute arbitrary code on the target system. The vulnerability was discovered by David Kierznowski and the exploit was written by e.b. The exploit has been tested on Windows XP SP2 (fully patched) with English language, IE6, and xupload.ocx version 3.0.0.4.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Persits XUpload and follow secure coding practices to prevent buffer overflow vulnerabilities.