an7isec.blogspot.co.il
http://an7isec.blogspot.co.il/2014/04/pown-noobs-acunetix-0day.html CVE-2014-2994
Acunetix 8 build 20120704 - Remote Stack Overflow
Record summary
CVE-2014-2994 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAcunetix 8 build 20120704 - Remote Stack OverflowExploitDB exploitby An7iNot analyzed1 file
References
8osandamalith.wordpress.com
http://osandamalith.wordpress.com/2014/04/24/pwning-script-kiddies-acunetix-buffer-overflow packetstormsecurity.com
http://packetstormsecurity.com/files/126306/Acunetix-8-Stack-Buffer-Overflow.html packetstormsecurity.com
http://packetstormsecurity.com/files/126307/Acunetix-8-Scanner-Buffer-Overflow.html acunetix.comConfirmation
http://www.acunetix.com/blog/news/misleading-reports-0-day-acunetix-wvs 32997exploit
http://www.exploit-db.com/exploits/32997 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-2994 youtube.com
https://www.youtube.com/watch?v=RHaMx8K1GeM