9.3
CVSSv2

CVE-2013-6874

Published: 26/11/2013 Updated: 27/11/2013
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in Vortex Light Alloy prior to 4.7.4 allows remote malicious users to execute arbitrary code via a long URL in a .m3u file.

Vulnerable Product Search on Vulmon Subscribe to Product

vortexgroup light alloy

Exploits

#!/usr/bin/perl ############################################################################################ # Exploit Title: Light Alloy 473 (m3u) - SEH Buffer Overflow (Unicode) # Date: 11-18-2013 # Exploit Author: Mike Czumak (T_v3rn1x) -- @SecuritySift # Vulnerable Software: Light Alloy v473 # Vendor Site: wwwlight-alloyru/ # Vu ...