vendor:
SCMPX
by:
HACK4LOVE
7,8
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: SCMPX
Affected Version From: 1.5.1
Affected Version To: 1.5.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
SCMPX 1.5.1 (.m3u File) Local Heap Overflow PoC
SCMPX 1.5.1 is vulnerable to a local heap overflow vulnerability. By creating a specially crafted .m3u file with 5000 'A' characters, an attacker can overwrite the EIP register and control the execution flow of the application.
Mitigation:
Upgrade to the latest version of SCMPX 1.5.1