18 lines
No EOL
708 B
Text
18 lines
No EOL
708 B
Text
Author: Karol Wiesek <karol [at] wiesek {dizd0t} pl>
|
|
Homepage: http://karol.wiesek.pl/
|
|
|
|
There exists two vulnerabilities in Panda Security ActiveScan 2.0 Update function.
|
|
1) typical overflow ( this exploit )
|
|
2) Update function allows to install any ( attacker suplied ) CABinet into victims system
|
|
|
|
Panda Security have not respond in any manner, thus i have no information of any patches, plans for patching ...
|
|
|
|
* UPDATE *
|
|
|
|
Panda has patched newest version, so update will not connect to custom ( attacker supplied ) URL.
|
|
|
|
Exploit:
|
|
http://karol.wiesek.pl/files/panda.tgz
|
|
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/6004.tgz (2008-panda.tgz)
|
|
|
|
# milw0rm.com [2008-07-04] |