# PoC

2 exploits Active since Mar 2014
CVE-2013-3928 METASPLOIT ruby WORKING POC
Chasys Draw IES < 4.11.02 - Remote Code Execution via Crafted BMP File
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.
CVE-2022-37042 METASPLOIT CRITICAL ruby WORKING POC
Zimbra Collaboration Suite 8.8.15/9.0 - Path Traversal & RCE via mboximport
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.
CVSS 9.8