Sysax 5.64 HTTP Remote Buffer Overflow
I have discovered a bug in the Sysax Multi-Server application. More specifically, it’s in the HTTP File Server service, which is not enabled by default. It has to be turned on by the admin for this exploit to properly function. The user in question also needs permission to create a directory.
In the Sysax service, the configuration would look like this:
To trigger this vulnerability is pretty simple. Log into the HTTP File Server: