PoC Index

CVE-2017-9544

CRITICAL 9.8EPSS 24.1%

There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
24.12% chance of exploitation in the next 30 days, 98th percentile
Published
2017-06-12
Updated
2024-08-05

Proof-of-concept exploits (2)

Metasploit modules (1)

References

Related