CVE-2013-6874
Light Alloy < 4.7.3 - Remote Code Execution via Long URL in .m3u File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6874. PoCs published by Mike Czumak.
AI-analyzed exploit summary This Perl script exploits a SEH-based buffer overflow vulnerability in Light Alloy 4.7.3 via a maliciously crafted .m3u file. It leverages Unicode-friendly shellcode and venetian alignment techniques to execute arbitrary code (calc.exe) on Windows XP SP3.
Description
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.
Exploits (1)
This Perl script exploits a SEH-based buffer overflow vulnerability in Light Alloy 4.7.3 via a maliciously crafted .m3u file. It leverages Unicode-friendly shellcode and venetian alignment techniques to execute arbitrary code (calc.exe) on Windows XP SP3.