CVE-2014-3791
Easy File Sharing Web Server 6.8 - Remote Code Execution via UserID Cookie Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-3791.
PoCs published by superkojiman, superkojiman, Julien Ahrens, including Metasploit module exploits/windows/http/efs_fmws_userid_bof.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in Easy File Sharing Web Server 6.8 by manipulating the UserID cookie to overwrite EDX and control execution flow, leading to arbitrary code execution. It uses a bruteforce approach to guess the correct stack address and delivers a bind shell on port 28876.
Description
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.
Exploits (2)
This exploit targets a stack buffer overflow in Easy File Sharing Web Server 6.8 by manipulating the UserID cookie to overwrite EDX and control execution flow, leading to arbitrary code execution. It uses a bruteforce approach to guess the correct stack address and delivers a bind shell on port 28876.
This Metasploit module exploits a stack buffer overflow in Easy File Management Web Server via the UserID cookie, allowing remote code execution. It includes version detection and multiple targets for different software versions.