vendor:
CamDo
by:
Achilles
7.5
CVSS
HIGH
SEH Local Exploit
CWE
Product Name: CamDo
Affected Version From: 3.7.2006
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:river_past:camdo:3.7.6
Platforms Tested: Windows XP SP3
2019
River Past CamDo SEH Local Exploit
This exploit allows an attacker to gain a bind shell on port 3110 by exploiting a vulnerability in River Past CamDo software. The exploit involves running a Python code, modifying a file within the software, and triggering the exploit.
Mitigation:
The vendor should release a patch to fix this vulnerability. In the meantime, users should avoid running the affected version of the software or should apply any available patches.