[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Panda Security ActiveScan 2.0 (Update) Remote BOF Exploit

Author
Karol Wiesek
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9216
Category
remote exploits
Date add
03-07-2008
Platform
unsorted
=========================================================
Panda Security ActiveScan 2.0 (Update) Remote BOF Exploit
=========================================================

Author:  	Karol Wiesek 

There exists two vulnerabilities in Panda Security ActiveScan 2.0 Update function.
1) typical overflow ( this exploit )
2) Update function allows to install any ( attacker suplied ) CABinet into victims system

Panda Security have not respond in any manner, thus i have no information of any patches, plans for patching ...

* UPDATE * 

Panda has patched newest version, so update will not connect to custom ( attacker supplied ) URL.

Exploit:

http://inj3ct0r.com/sploits/9216.tgz




#  0day.today [2024-11-16]  #