Exploitation Summary
EIP tracks 2 public exploits for CVE-2014-2206.
PoCs published by Julien Ahrens, Julien Ahrens, Gabor Seljan, bzyo, sinn3r, including Metasploit module exploits/windows/browser/getgodm_http_response_bof.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in GetGo Download Manager v4.9.0.1982 via a maliciously crafted HTTP response header. It leverages SEH overwrite and SafeSEH bypass to execute arbitrary shellcode (calc.exe payload).
Description
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.
Exploits (2)
This exploit targets a buffer overflow vulnerability in GetGo Download Manager v4.9.0.1982 via a maliciously crafted HTTP response header. It leverages SEH overwrite and SafeSEH bypass to execute arbitrary shellcode (calc.exe payload).
This Metasploit module exploits a stack-based buffer overflow in GetGo Download Manager via an overly long HTTP response header. It includes two exploit methods for versions 4.9.0.1982 and 5.3.0.2712, leveraging SEH overwrites and structured payload delivery.