packetstormsecurity.com
http://packetstormsecurity.com/files/162008/SyncBreeze-10.1.16-Buffer-Overflow.html CVE-2017-15950
HIGH
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
Record summary
CVE-2017-15950 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBSyncBreeze 10.1.16 - XML Parsing Stack-based Buffer OverflowExploitDB exploitby Filipe OliveiraNot analyzed1 file
Repository PoCs
GitHubrnnsz/CVE-2017-15950Repository PoCby rnnszStars: 0Not analyzed4 files
References
3seclists.org
http://seclists.org/fulldisclosure/2017/Oct/64 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-15950