Description
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system.
Problem types
Product status
Credits
Kirill Nikolaev
References
www.exploit-db.com/exploits/47759 (ExploitDB-47759)
www.nsauditor.com/ (Vendor Homepage)
www.exploit-db.com/exploits/47719 (Original DOS Exploit Reference)
www.vulncheck.com/...tauditor-base-local-buffer-overflow-seh (VulnCheck Advisory: SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH))