CVE-2013-6874

Light Alloy < 4.7.3 - Remote Code Execution via Long URL in .m3u File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-6874. PoCs published by Mike Czumak.

AI-analyzed exploit summary This Perl script exploits a SEH-based buffer overflow vulnerability in Light Alloy 4.7.3 via a maliciously crafted .m3u file. It leverages Unicode-friendly shellcode and venetian alignment techniques to execute arbitrary code (calc.exe) on Windows XP SP3.

Description

Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mike Czumak · perllocalwindows
https://www.exploit-db.com/exploits/29777

This Perl script exploits a SEH-based buffer overflow vulnerability in Light Alloy 4.7.3 via a maliciously crafted .m3u file. It leverages Unicode-friendly shellcode and venetian alignment techniques to execute arbitrary code (calc.exe) on Windows XP SP3.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Light Alloy v4.7.3
No auth needed
Prerequisites: Victim must open the malicious .m3u file in Light Alloy 4.7.3
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/29777
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63895

Scores

EPSS 0.3515
EPSS Percentile 97.2%

Details

CWE
CWE-119
Status published
Products (1)
vortexgroup/light_alloy < 4.7.3
Published Nov 26, 2013
Tracked Since Feb 18, 2026