CVE-2010-1688
SyncBack Freeware < 3.2.21 - Stack-based Buffer Overflow via Long Filename in Profile
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1688. PoCs published by Lincoln.
AI-analyzed exploit summary This exploit targets a SEH-based buffer overflow vulnerability in SyncBack Freeware V3.2.20.0. It crafts a malicious .sps file with a payload that triggers a structured exception handler overwrite, leading to arbitrary code execution.
Description
Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.
Exploits (1)
This exploit targets a SEH-based buffer overflow vulnerability in SyncBack Freeware V3.2.20.0. It crafts a malicious .sps file with a payload that triggers a structured exception handler overwrite, leading to arbitrary code execution.