9.3
CVSSv2

CVE-2008-6897

Published: 05/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) "a" HTML tag; a long src attribute in (2) embed, (3) img, or (4) script tags; (5) a long background attribute in a body tag; and other unspecified tags.

Vulnerable Product Search on Vulmon Subscribe to Product

andres garcia getleft 1.2

Exploits

#!/usr/bin/perl # # Getleft v1200 DoS PoC # Author: Koshi # # Application: Getleft v12 # Publisher: Andres Garcia ( personal1iddeoes/andresgarci/getleft/english/indexhtml ) # Description: Website Downloader, for such things as offline browsing # Tested On: Windows XP SP2 # # Module: Getleftexe # eax=00c5f170 ebx=00000000 ecx=0000000 ...