6.8
CVSSv2

CVE-2017-7310

Published: 29/03/2017 Updated: 08/03/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 695
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A buffer overflow vulnerability in Import Command in SyncBreeze prior to 10.6, DiskSorter prior to 10.6, DiskBoss prior to 8.9, DiskPulse prior to 10.6, DiskSavvy prior to 10.6, DupScout prior to 10.6, and VX Search prior to 10.6 allows malicious users to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.

Vulnerable Product Search on Vulmon Subscribe to Product

flexense syncbreeze 9.5.16

flexense disksorter 9.5.12

flexense diskboss 7.8.16

Exploits

Disk Pulse Enterprise version 10418 suffers from an import command buffer overflow vulnerability ...
## # This module requires Metasploit: metasploitcom/download # Current source: githubcom/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote Rank = NormalRanking include Msf::Exploit::FILEFORMAT include Msf::Exploit::Remote::Seh def initialize(info = {}) super(update_info(info, 'Nam ...
#!/usr/bin/env python # Exploit Title: Sync Breeze Enterprise 9516 - 'Import Command' Buffer Overflow (SEH) # Date: 2017-03-29 # Exploit Author: Daniel Teixeira # Author Homepage: wwwdanielteixeiracom # Vendor Homepage: wwwsyncbreezecom # Software Link: wwwsyncbreezecom/setups/syncbreezeent_setup_v9516exe # Version: 9516 ...
#!/usr/bin/env python # Exploit Title: Disk Pulse Enterprise v10418 - 'Import Command' Buffer Overflow (SEH) # Date: 2018-01-22 # Exploit Author: Daniel Teixeira # Author Homepage: wwwdanielteixeiracom # Vendor Homepage: wwwdiskpulsecom # Software Link: wwwdiskpulsecom/setups/diskpulseent_setup_v10418exe # Version: 10416 ...