vendor:
Quick Search
by:
Tomislav Paskalev
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Quick Search
Affected Version From: 1.1.0.189
Affected Version To: 1.1.0.189
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 EN
2015
Quick Search 1.1.0.189 ‘search textbox’ Unicode SEH egghunter Buffer Overflow
Quick Search 1.1.0.189 contains a buffer overflow vulnerability in the 'search textbox' which can be exploited by an attacker to execute arbitrary code by using a specially crafted exploit string. The exploit string contains an egghunter which searches the memory for the marker and executes the shellcode once found. The exploit should work across different OS versions.
Mitigation:
Update to the latest version of Quick Search.