Exploit YardRadius - Multiple Local Format String Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
38672
Проверка EDB
  1. Пройдено
Автор
HAMID ZAMANI
Тип уязвимости
LOCAL
Платформа
WINDOWS
CVE
cve-2013-4147
Дата публикации
2013-06-30
YardRadius - Multiple Local Format String Vulnerabilities
Код:
source: https://www.securityfocus.com/bid/61356/info

YardRadius is prone to multiple local format-string vulnerabilities.

Local attackers can leverage these issues to cause denial-of-service conditions. Due to nature of these issues, arbitrary code-execution within the context of the vulnerable application may also be possible.

YardRadius 1.1.2-4 is vulnerable; other versions may also be possible.

The following proof-of-concept is available:

ln -s radiusd %x

./%x -v
 
Источник
www.exploit-db.com

Похожие темы