code-projects Police FIR Record Management System
cpe:2.3:a:code-projects:police_fir_record_management_system:*:*:*:*:*:*:*
- 1.0
A critical stack-based buffer overflow vulnerability has been identified in the Police FIR Record Management System version 1.0. The issue arises in the Delete Record Handler component, where the filename parameter in the deleterecord function can be manipulated without proper length restrictions. This vulnerability requires local exploitation and has been publicly disclosed.
Exploitation of this vulnerability leads to a stack-based buffer overflow, causing a crash and potentially allowing for arbitrary code execution.
To reproduce this vulnerability, access the application and navigate to the Delete Record function. Enter a payload into the filename parameter that exceeds the 16-byte limit, which will cause a stack overflow. After the overflow, an 'EXCEPTION_ACCESS_VIOLATION' error will be encountered, indicating a successful exploitation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.