A stack-based buffer overflow exists in MiniShare 1.4.1 due to improper handling of HTTP CONNECT requests. This vulnerability allows an attacker to send a specially crafted HTTP CONNECT request that overflows a stack buffer, leading to arbitrary code execution. The vulnerability is similar to CVE-2018-19862 and CVE-2018-19861. MiniShare is discontinued and no longer maintained.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a structured educational exploit-development walkthrough for CVE-2020-13768, a stack-based buffer overflow in MiniShare 1.4.1 reachable via an unauthenticated HTTP PUT request. It is not a framework module; it is a standalone set of Python 3 scripts plus Markdown documentation. Repository structure: the top-level README explains the vulnerability, affected product, and exploitation rationale. The Vulnerability/README.md file provides the step-by-step methodology. The Vulnerability/Exploit/ directory contains seven Python scripts that mirror a standard exploit-development progression: (1) basic connectivity and PUT request validation, (2) fuzzing oversized URI paths to trigger a crash, (3) cyclic-pattern delivery to find the EIP offset, (4) confirmation of EIP control using BBBB at offset 1786, (5) bad-character testing, (6) redirection of execution through a debugger-found JMP/CALL ESP gadget with NOP/INT3 markers, and (7) a final exploit that appends a NOP sled and embedded shellcode after the EIP overwrite. Main exploit capabilities: the code targets a network-facing Windows HTTP service on TCP/80 and abuses the PUT URI path as the overflow vector. The scripts demonstrate remote crash induction, precise EIP overwrite, bad-character analysis, gadget-based control-flow hijacking, and final shellcode execution. The final script is operational in a lab context because it includes a hardcoded gadget address and shellcode, but the comments make clear that gadget addresses are debugger/session dependent on modern Windows systems with ASLR, so it is best understood as a teaching/lab exploit rather than a universally reliable one-click weapon. Fingerprintable targets/endpoints: all exploit scripts default to 127.0.0.1:80 and construct raw HTTP PUT requests with the Host header set to 127.0.0.1. The vulnerable logical endpoint is the PUT request URI path itself. Additional notable observables include the documented EIP offset 1786, bad characters \x00/\x0a/\x0d, example debugger artifact paths under C:\Mona and Immunity Debugger, and example reverse-shell callback values 192.168.1.10:443 in the methodology notes. Overall purpose: this is a genuine exploit repository intended for training and demonstration of classic remote stack overflow exploitation against MiniShare 1.4.1, culminating in remote code execution through a crafted HTTP PUT request.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.