CVE-2019-25319
Last modified
CVE-2019-25319 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2019-25319?
How severe is CVE-2019-25319?
How do I fix CVE-2019-25319?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-25313FlexNet Publisher 11.12.1 contains a cross-site request forg…5.1
- CVE-2019-25314Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persi…5.5
- CVE-2019-25315WordPress Server Log Viewer 1.0 contains a persistent cross-…6.4
- CVE-2019-25316GOautodial 4.0 contains a persistent cross-site scripting vu…6.4
- CVE-2019-25317Kimai 2 contains a persistent cross-site scripting vulnerabi…5.4
- CVE-2019-25318AVS Audio Converter 9.1.2.600 contains a stack overflow vuln…8.8
- CVE-2019-2532Vulnerability in the MySQL Server component of Oracle MySQL …4.9
- CVE-2019-25320E Learning Script 1.0 contains an authentication bypass vuln…8.8
- CVE-2019-25321FTP Navigator 8.03 contains a stack overflow vulnerability t…9.8
- CVE-2019-25322Heatmiser Netmonitor 3.03 contains a hardcoded credentials v…9.3
- CVE-2019-25323Heatmiser Netmonitor v3.03 contains an HTML injection vulner…6.1
- CVE-2019-25324RICOH Web Image Monitor 1.09 contains an HTML injection vuln…6.1
Are you affected by CVE-2019-25319?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
