CORE IMPACT v7.5 - Exploits Update (Fri Jul 18 2008)
Download Accelerator Plus M3U Buffer Overflow Exploit
Exploits/Client Side [Windows]
Fri Jul 18 2008
This module exploits a vulnerability in Download Accelerator Plus when importing a M3U file (MP3 Playlist) and verify option is used, may allow a remote unprivileged user who provides a crafted M3U document that is opened by a local user to execute arbitrary commands on the system with the privileges of the user running Download Accelerator Plus. This can be exploited to cause a stack based buffer overflow when a specially crafted file is imported and the verify button is used in DAP.
Exploits Vulnerabiltiy: CVE-2008-3182











