Description
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can craft a specially designed payload to trigger remote code execution, demonstrating the ability to run system commands like launching the calculator.
Problem types
Product status
Credits
ZwX
References
www.exploit-db.com/exploits/48050 (ExploitDB-48050)
www.wedding-slideshow-studio.com/ (Wedding Slideshow Studio Official Homepage)
www.vulncheck.com/...g-slideshow-studio-name-buffer-overflow (VulnCheck Advisory: Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow)