vendor:
POP Peeper
by:
Un_N0n
7,8
CVSS
HIGH
SEH Over-write
119
CWE
Product Name: POP Peeper
Affected Version From: v4.0.1
Affected Version To: v4.0.1
Patch Exists: YES
Related CWE: N/A
CPE: a:esumsoft:pop_peeper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86(32 BIT)
2015
POP Peeper SEH Over-write
POP Peeper is vulnerable to SEH Over-write. An attacker can exploit this vulnerability by creating a malicious file with a long string of characters and entering it in the Account Name field when creating a new account. The attacker can then compose a new mail with the same malicious string in the TO and Subject fields. When the attacker saves the mail as a draft, the application will crash. Everytime the attacker clicks on the Check Mail option, the application will crash as it will load the saved DRAFT.
Mitigation:
The vendor has released a patch to address this vulnerability.