vendor:
Sysax Multi Server
by:
Craig Freyman (@cd1zz)
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sysax Multi Server
Affected Version From: 5.5
Affected Version To: 5.5
Patch Exists: YES
Related CWE:
CPE: sysax_multi_server
Platforms Tested: Windows XP SP3 32bit, Server 2003 SP2 32bit
2012
Sysax Multi Server 5.50 Create Folder BOF
This exploit allows an attacker to create a folder with a specially crafted SID parameter in the Sysax Multi Server version 5.50. The vulnerability was discovered on January 13, 2012 and a fix was released on January 17, 2012 in version 5.52. The exploit has been tested on XP SP3 32bit and Server 2003 SP2 32bit without DEP.
Mitigation:
Update to version 5.52 or later to fix the vulnerability.