CVE-2018-25221
CRITICALEChat Server 3.1 Buffer Overflow via chat.ghp username Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25221. PoCs published by Juan Sacco.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Easy Chat Server v3.1 via the 'username' parameter in the 'chat.ghp' endpoint. It constructs a malicious HTTP GET request with a crafted payload containing a NOP sled, SEH overwrite, and shellcode to achieve remote code execution.
Description
EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Easy Chat Server v3.1 via the 'username' parameter in the 'chat.ghp' endpoint. It constructs a malicious HTTP GET request with a crafted payload containing a NOP sled, SEH overwrite, and shellcode to achieve remote code execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H