vendor:
Not specified
by:
Stefan Esser
7.5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: Not specified
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not provided
CPE: Not specified
Platforms Tested: Not specified
2007
PHP zip:// URL Wrapper Stack Buffer Overflow
This code demonstrates a stack buffer overflow vulnerability in the PHP zip:// URL Wrapper. By constructing a specially crafted filename, an attacker can trigger the vulnerability and potentially execute arbitrary code on the target system. The code includes a bindshell payload on port 4444 from Metasploit.
Mitigation:
Apply patches or updates from the vendor. Avoid using the zip:// URL Wrapper.