vendor:
Sysax Multi Server
by:
Craig Freyman
N/A
CVSS
HIGH
SEH Exploit
119
CWE
Product Name: Sysax Multi Server
Affected Version From: 5.53
Affected Version To: 5.53
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: Windows XP SP3 32-bit
2012
Sysax Multi Server 5.53 SFTP Post Auth SEH Exploit (Egghunter)
This exploit allows an attacker to execute arbitrary code on a Sysax Multi Server version 5.53 after authentication. The exploit takes advantage of a buffer overflow vulnerability in the software.
Mitigation:
Update to version 5.55 or later to fix the vulnerability.