Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2017-15950 PoC — Flexense SyncBreeze Enterprise 缓冲区错误漏洞

Source
Associated Vulnerability
Title: Flexense SyncBreeze Enterprise 缓冲区错误漏洞 (CVE-2017-15950)
Description:Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destination directory" field, either within an XML document or through use of passive mode.
Readme
# CVE-2017-15950

PoC exploit for vulnerability CVE-2017-15950 SyncBreeze XML Parser and/or Sync functionality Stack-Based Buffer Overflow.

## Usage

When running the XML payload generator, the script will output a XML file **xplSyncBreeze.xml** containing the payload to import using SyncBreeze.

```bash
python3 payloadgenerator_XML_CVE-2017-15950.py
```

When running the default payload generator, the script will output a TXT file **POCPayload.txt** containing the payload to insert into Sync functionality Destination PATH or Source PATH fields.

```bash
python3 payloadgenerator_CVE-2017-15950.py
```

## Acknowledgments

Exploits developed with Filipe Oliveira and Toronto Garcez.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →