github.com
https://github.com/bitfu/uc-httpd-1.0.0-buffer-overflow-exploit CVE-2018-10088
CRITICALNuclei
xiongmaitech uc-httpd Improper Restriction of Operations within the Bounds of a Memory Buffer
Record summary
CVE-2018-10088 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
uc-httpdBrowse xiongmaitech / uc-httpd | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBXiongMai uc-httpd 1.0.0 - Buffer OverflowExploitDB exploitby Andrew WatsonNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALXiongMai uc-httpd 1.0.0 - Buffer OverflowCVSS 9.8
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
Impact
Potential for remote code execution or denial of service when successfully exploited.
Remediation
Update to the latest version of uc-httpd or apply security patches provided by the vendor.
WeaknessesCWE-119
Authors0x_Akoko
Template tagscvecve2018xiongmaibuffer-overflowrcepassivevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:xiongmaitech:uc-httpd:1.0.0:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:xiongmaitech:uc-httpd"
https://nvd.nist.gov/vuln/detail/CVE-2018-10088 https://www.exploit-db.com/exploits/44864 https://github.com/bitfu/uc-httpd-1.0.0-buffer-overflow-exploit https://github.com/KostasEreksonas/Besder-6024PB-XMA501-ip-camera-security-investigation
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-10088 44864exploit
https://www.exploit-db.com/exploits/44864