Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-20038. PoCs published by Juan Sacco.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in yTree v1.94-1.1, leveraging a crafted input to overwrite the EIP and execute arbitrary shellcode. The PoC includes a shellcode payload for spawning a shell and is tested on Kali Linux 2.0 x86.
Description
yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an excessively long argument to the application. Attackers can craft a malicious command-line argument containing shellcode and a return address to overwrite the stack and execute code in the application context.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in yTree v1.94-1.1, leveraging a crafted input to overwrite the EIP and execute arbitrary shellcode. The PoC includes a shellcode payload for spawning a shell and is tested on Kali Linux 2.0 x86.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H