vendor:
UFO: Alien Invasion
by:
dookie
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: UFO: Alien Invasion
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:ufo_alien_invasion:ufo_alien_invasion
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MacOSX
2009
UFO: Alien Invasion v2.2.1 IRC Client Remote Code Execution – MacOSX
This exploit is a remote code execution vulnerability in UFO: Alien Invasion v2.2.1 IRC Client on MacOSX. It uses a combination of msfpayload and msfencode to generate a shellcode payload, which is then sent to the vulnerable application via an IRC message. The payload is then executed on the target system, allowing the attacker to gain remote access.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to the latest version of UFO: Alien Invasion, which is not vulnerable to this exploit.