ID
VAR-E-201110-0215
TITLE
IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities
Trust: 0.3
DESCRIPTION
IRAI AUTOMGEN is prone to multiple remote code-execution vulnerabilities because it fails to properly validate user-supplied input.
Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploits can trigger a denial-of-service condition.
AUTOMGEN 8.0.0.7 is vulnerable; other versions may also be affected.
Trust: 0.3
AFFECTED PRODUCTS
vendor: | irai | model: | automgen | scope: | eq | version: | 8.0.0.7 | Trust: 0.3 |
EXPLOIT
The following proof of concept is available:
Bullet list:
<li><a href="/data/vulnerabilities/exploits/50045.zip">/data/vulnerabilities/exploits/50045.zip</a></li>
Trust: 0.3
PRICE
Free
Trust: 0.3
TYPE
Input Validation Error
Trust: 0.3
CREDITS
Luigi Auriemma
Trust: 0.3
EXTERNAL IDS
db: | BID | id: | 50045 | Trust: 0.3 |
REFERENCES
url: | http://www.irai.com/a8e/ | Trust: 0.3 |
SOURCES
db: | BID | id: | 50045 |
LAST UPDATE DATE
2022-07-27T09:43:05.069000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 50045 | date: | 2011-10-10T00:00:00 |
SOURCES RELEASE DATE
db: | BID | id: | 50045 | date: | 2011-10-10T00:00:00 |