Domain Quester Pro Stack Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack overflow vulnerability has been identified in Domain Quester Pro version 6.02. This vulnerability allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Exploitation involves crafting a malicious payload that targets the 'Domain Name Keywords' input field, triggering an access violation that can be exploited to execute a bind shell on port 9999.

Impact

Exploitation of this vulnerability leads to arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, first generate a payload that will create a bind shell listening on TCP port 9999. This can be done using a Python script that incorporates shellcode into a text file. Once the payload is prepared, copy the contents of the file into the clipboard. After that, install and open Domain Quester Pro 6.02. In the application, navigate to the 'Domain Name Keywords' section and paste the payload into the provided textbox. Clicking 'OK' will trigger the vulnerability, causing the program to freeze while the bind shell is activated in the background.

Added: Feb 12, 2026, 11:33 PM
Updated: Feb 12, 2026, 11:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.6
remediation
0.0
relevance
2.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.