vendor:
Free Download Manager
by:
Praveen Darshanam
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Free Download Manager
Affected Version From: 2.5 Build 758
Affected Version To: 3.0 Build 844
Patch Exists: YES
Related CWE: CVE-2009-0183
CPE: a:free_download_manager:free_download_manager
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/http/fdm_auth_header, https://www.infosecmatter.com/nessus-plugin-library/?id=18262, https://www.infosecmatter.com/nessus-plugin-library/?id=48265, https://www.infosecmatter.com/nessus-plugin-library/?id=47119, https://www.infosecmatter.com/nessus-plugin-library/?id=68055, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MS Windows
2009
Stack-based buffer overflow in Remote Control Server in Free Download Manager
A stack-based buffer overflow vulnerability in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.
Mitigation:
Ensure that the Authorization header is properly validated and sanitized before being used.