packetstormsecurity.com
http://packetstormsecurity.com/files/154586/File-Sharing-Wizard-1.5.0-SEH-Buffer-Overflow.html CVE-2019-16724
CRITICAL
File Sharing Wizard 1.5.0 - POST SEH Overflow
Record summary
CVE-2019-16724 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits and 1 repository PoC.
Description
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.
Description source: CVE List
Exploitation context
Proofs of concept
3Catalogued exploits
ExploitDBFile Sharing Wizard 1.5.0 - POST SEH OverflowExploitDB exploitby x00pwnNot analyzed1 file
MetasploitFile Sharing Wizard - POST SEH OverflowMetasploit exploitby Dean Welch <dean_welch@rapid7.com> +1 moreNot analyzed1 file
Repository PoCs
GitHubnanabingies/CVE-2019-16724Repository PoCby nanabingiesStars: 2Not analyzed2 files
References
4packetstormsecurity.com
http://packetstormsecurity.com/files/154777/File-Sharing-Wizard-1.5.0-POST-SEH-Overflow.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16724 Exploit Databaseexploit
https://www.exploit-db.com/exploits/47412