Description
Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field.
Problem types
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
7.7.14
Credits
Paras Bhatia
References
www.exploit-db.com/exploits/48279 (Exploit Database Entry 48279)
www.diskboss.com/ (Official Product Homepage)
github.com/...s_7.7.14/raw/master/diskboss_setup_v7.7.14.exe (Software Link Download)
github.com/x00x00x00x00/diskboss_7.7.14/raw/master/ (GitHub Repository)
www.vulncheck.com/...oss-add-input-directory-buffer-overflow