|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Buffer overflow in WebSite Professional's webfind.exe Vulnerability Assessment Details
|
Buffer overflow in WebSite Professional's webfind.exe |
||
|
Buffer overflow attempt Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a CGI script that is affected by a buffer overflow flaw. Description : The 'webfind.exe' CGI script on the remote host is vulnerable to a buffer overflow when given a too long 'keywords' argument. This problem permits a possible hacker to execute arbitrary code as root on this host. See also : http://archives.neohapsis.com/archives/bugtraq/2000-07/0268.html Solution : Upgrade to WebSite Professional 2.5 or delete this CGI. Network Security Threat Level: Critical / CVSS Base Score : 10 (AV:R/AC:L/Au:NR/C:C/A:C/I:C/B:N) Networks Security ID: 1487 Vulnerability Assessment Copyright: This script is Copyright (C) 2000 Renaud Deraison |
||
|
Storage Equipment, NAS, SAN |
|
||
|
No Discussions have been posted on this vulnerability. |