CVE-2018-19861
CRITICALminishare < 1.4.1 - Remote Code Execution via Long HTTP HEAD Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19861. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in MiniShare 1.4.1 via a long HTTP POST request, leading to remote code execution. It uses an egghunter technique to locate and execute shellcode due to limited space in the ESP register.
Description
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in MiniShare 1.4.1 via a long HTTP POST request, leading to remote code execution. It uses an egghunter technique to locate and execute shellcode due to limited space in the ESP register.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H