Author: Karol Wiesek <karol [at] wiesek {dizd0t} pl>
Homepage: http://karol.wiesek.pl/
There exists two vulnerabilities in Panda Security ActiveScan 2.0 Update function.
1) typical overflow ( this exploit )
2) Update function allows to install any ( attacker suplied ) CABinet into victims system
Panda Security have not respond in any manner, thus i have no information of any patches, plans for patching ...
* UPDATE *
Panda has patched newest version, so update will not connect to custom ( attacker supplied ) URL.
Exploit:
http://karol.wiesek.pl/files/panda.tgz
http://exploit-db.com/sploits/2008-panda.tgz
http://sebug.net/paper/poc/2008-panda.tgz
暂无评论