Vulnerabilities > CVE-2007-1074 - Remote Buffer Overflow vulnerability in NewsBin Pro NBI File

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
dji
critical
exploit available

Summary

Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long (1) DataPath or (2) DownloadPath attributed in a (a) NBI file, or (3) a long group field in a (b) NZB file. Successful exploitation allows execution of arbitrary code, but requires that the user is tricked into e.g. loading a malicious NBI configuration file.

Vulnerable Configurations

Part Description Count
Application
Dji
2

Exploit-Db

descriptionNews Bin Pro 5.33 (.NBI File) Local Buffer Overflow Exploit. CVE-2007-1074. Local exploit for windows platform
fileexploits/windows/local/3349.c
idEDB-ID:3349
last seen2016-01-31
modified2007-02-21
platformwindows
port
published2007-02-21
reporterMarsu
sourcehttps://www.exploit-db.com/download/3349/
titleNews Bin Pro 5.33 - .NBI Local Buffer Overflow Exploit
typelocal