vendor:
ZipCentral
by:
Jiten Pathy
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ZipCentral
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:zipcentral
Platforms Tested:
2010
ZipCentral Filename Handling Buffer Overflow Exploit
This exploit takes advantage of a buffer overflow vulnerability in the filename handling of ZipCentral. It uses an address from the executable file for SEH, which is reliable across different platforms. The exploit includes an egghunter shellcode and a custom decoder to execute the necessary instructions.
Mitigation:
Apply the latest security patches for ZipCentral to fix the buffer overflow vulnerability.