CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
96.8%
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.
Vendor | Product | Version | CPE |
---|---|---|---|
shemes | grabit | * | cpe:2.3:a:shemes:grabit:*:beta3:*:*:*:*:*:* |
shemes | grabit | 1.5.0 | cpe:2.3:a:shemes:grabit:1.5.0:beta:*:*:*:*:*:* |
shemes | grabit | 1.5.1 | cpe:2.3:a:shemes:grabit:1.5.1:beta:*:*:*:*:*:* |
shemes | grabit | 1.5.2 | cpe:2.3:a:shemes:grabit:1.5.2:beta:*:*:*:*:*:* |
shemes | grabit | 1.5.3 | cpe:2.3:a:shemes:grabit:1.5.3:beta:*:*:*:*:*:* |
shemes | grabit | 1.6.1 | cpe:2.3:a:shemes:grabit:1.6.1:beta:*:*:*:*:*:* |
shemes | grabit | 1.6.2 | cpe:2.3:a:shemes:grabit:1.6.2:beta:*:*:*:*:*:* |
shemes | grabit | 1.7.1 | cpe:2.3:a:shemes:grabit:1.7.1:beta:*:*:*:*:*:* |
shemes | grabit | 1.7.2 | cpe:2.3:a:shemes:grabit:1.7.2:beta:*:*:*:*:*:* |
shemes | grabit | 1.7.2 | cpe:2.3:a:shemes:grabit:1.7.2:beta2:*:*:*:*:*:* |
blog.teusink.net/2009/05/grabit-172-beta-3-nzb-file-parsing.html
osvdb.org/54205
secunia.com/advisories/34893
www.securityfocus.com/archive/1/503184/100/0/threaded
www.securityfocus.com/bid/34807
www.securitytracker.com/id?1022161
www.shemes.com/index.php?p=whatsnew
www.vupen.com/english/advisories/2009/1243
exchange.xforce.ibmcloud.com/vulnerabilities/50310
www.exploit-db.com/exploits/8612