Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-0261.
PoCs published by His0k4, Mike Czumak, including Metasploit module exploits/windows/fileformat/total_video_player_ini_bof.
AI-analyzed exploit summary This exploit targets a local stack overflow vulnerability in Total Video Player V1.31 by crafting a malicious .ini file. It uses a Metasploit-generated shellcode to execute arbitrary commands (e.g., calc.exe) via a structured exception handler (SEH) overwrite.
Description
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.
Exploits (2)
This exploit targets a local stack overflow vulnerability in Total Video Player V1.31 by crafting a malicious .ini file. It uses a Metasploit-generated shellcode to execute arbitrary commands (e.g., calc.exe) via a structured exception handler (SEH) overwrite.
This Metasploit module exploits a SEH-based buffer overflow in Total Video Player 1.3.1 by crafting a malicious 'Settings.ini' file. The exploit leverages a controlled SEH overwrite to achieve arbitrary code execution when the file is parsed.