A stack-based buffer overflow vulnerability exists in Easy File Sharing (EFS) Web Server 7.2. The vulnerability is triggered when a specially crafted POST request is sent to the forum.ghp endpoint during the creation of a new forum topic. This allows remote attackers to overflow a stack buffer and execute arbitrary code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a step-by-step exploit-development walkthrough for CVE-2018-18912 affecting Easy File Sharing Web Server 7.2 on Windows. It is not a framework module; it is a standalone educational exploit repo composed mainly of eight Python scripts under Vulnerability/Exploit and supporting Markdown documentation. The structure is pedagogical: 01Python3Connection.py verifies authenticated connectivity to the target forum endpoint; 02Python3Fuzzing.py increases the author field length until the service crashes; 03Python3SEHOffsetDiscovery.py sends a cyclic pattern to identify the nSEH/SEH offset; 04Python3ControlleNSEHAndSEH.py confirms control of both records; 05Python3PopPopRet.py uses a hardcoded POP POP RET gadget from ImageLoad.dll at 0x100194B2; 06Python3ShortJump.py replaces the debug nSEH bytes with a short jump to reach attacker-controlled data; 07Python3FindBadChars.py sends a full byte array for bad-character analysis; and 08Python3Shellcode.py delivers the final exploit buffer with embedded Windows shellcode. The exploit capability is remote authenticated code execution via a stack-based SEH overwrite in the author POST parameter sent to /forum.ghp?forumid=1 over HTTP on port 80. The code consistently uses raw Python sockets and manually constructs HTTP requests with Cookie headers containing UserID, PassWD, and SESSIONID values. The exploit assumes a target environment where ImageLoad.dll is loaded without modern mitigations such as ASLR and SafeSEH, enabling a reliable SEH handler overwrite. The final script is operational rather than merely demonstrative because it includes a complete exploit buffer and shellcode, though the payload is hardcoded and not parameterized. The documentation also references optional extension to DEP bypass/ROP and reverse-shell payload generation, but the included final Python exploit specifically demonstrates direct shellcode execution after SEH hijack.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.