CVE-2019-25319
CRITICALDomain Quester Pro 6.02 - Remote Code Execution via Domain Name Keywords Input
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25319. PoCs published by boku.
AI-analyzed exploit summary This exploit leverages a stack overflow vulnerability in Domain Quester Pro 6.02 via SEH overwrite to execute a bind shell payload. The payload is generated using msfvenom and avoids bad characters to ensure successful execution.
Description
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.
Exploits (1)
This exploit leverages a stack overflow vulnerability in Domain Quester Pro 6.02 via SEH overwrite to execute a bind shell payload. The payload is generated using msfvenom and avoids bad characters to ensure successful execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H