9.3
CVSSv2

CVE-2011-0500

Published: 20/01/2011 Updated: 21/01/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and previous versions; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote malicious users to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element with a long "value" attribute, as demonstrated using a valitem with the mp3 name.

Vulnerable Product Search on Vulmon Subscribe to Product

verytools videospirit lite 1.4.0.1

verytools videospirit pro 1.6.8.1

verytools videospirit pro

Exploits

## # $Id: videospirit_visprjrb 12305 2011-04-11 23:32:41Z sinn3r $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' c ...
# Exploit Title: VideoSpirit Pro v168 Local BoF Exploit # Date: 01/08/2011 # Author: xsploitedsec # URL: wwwx-sploitedcom/ # Contact: xsploitedsec[at]x-sploitedcom # Software Link: wwwverytoolscom/videospirit/downloadhtml # Vulnerable version: v168 # Tested on: Windows XP SP3 Eng # Software description # # "VideoSpirit Pro is ...