bd249d1f28
The exploit was not working due to the user's root path causing the EIP offset to change. To correct this, I was able to get the server to disclose the root path in an error message (fixed in 5.67). I also radically refactored the exploit due to the feedback I received from Juan Vazquez.