← Advisories

Epiri Professional Web Browser 3.0 Remote Crash Exploit

Low
Advisory ID
ZSL-2009-4923
Release Date
30 July 2009
Vendor
Horizon Software Co. - http://www.horizonum.com
Affected Version
3.0.0.00
CVE
N/A
Tested On
Microsoft Windows XP Professional SP3 (English)
Summary

Epiri Professional 3.0 next generation alternative internet Epiri Professional features with faster internet, digital clarity, the latest technological design and user-focused, impressive, next generation alternative internet program. Microsoft Silverlight needed.

Description

Epiri Professional Web Browser suffers from a denial of service vulnerability that crashes the application by typiing one of the 3 vulnerable strings into the address bar ('file://', 'C::' and 'C:AAAA..AAA[257]) or by opening a malicious .vbs script file localy or remotely. Vulnerable Mode: Browse Internet.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
Exploit coded by sm
References
Changelog
30.07.2009Initial release