CVE-2009-1627
Streaming Download Project Downloader 2.3.0 - Remote Code Execution via Long ASF URL in ASX File
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2009-1627. PoCs published by SimO-s0fT, His0k4, Cyber-Zone.
AI-analyzed exploit summary This exploit targets a local buffer overflow vulnerability in SDP Downloader via a crafted .asx file. It leverages SEH overwrite with a NOP sled and shellcode to achieve arbitrary code execution.
Description
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file.
Exploits (3)
This exploit targets a local buffer overflow vulnerability in SDP Downloader via a crafted .asx file. It leverages SEH overwrite with a NOP sled and shellcode to achieve arbitrary code execution.
This exploit targets a local buffer overflow vulnerability in SDP Downloader v2.3.0 via a malformed .ASX file. It leverages SEH overwrite with a custom shellcode to execute arbitrary commands (e.g., calc.exe).
This exploit is a proof-of-concept for a heap overflow vulnerability in SDP Downloader v2.3.0. It generates a malicious ASX file with an overly long URL to trigger the overflow, potentially leading to remote code execution.