Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gist.github.com/apple502j/193358682885fe1a6708309ce934e4ed | third party advisory exploit |
https://github.com/MommyHeather/AdvancedBackups/commit/1545f499f73bf434ed292c31121fdda8042ff5d6 | patch |