Exploit myServer 0.6.2 - 'math_sum.mscgi' Multiple Remote Overflows

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
24337
Проверка EDB
  1. Пройдено
Автор
DR_INSANE
Тип уязвимости
REMOTE
Платформа
CGI
CVE
null
Дата публикации
2004-07-30
myServer 0.6.2 - 'math_sum.mscgi' Multiple Remote Overflows
Код:
source: https://www.securityfocus.com/bid/10831/info
 
Reportedly MyServer is affected by multiple remote vulnerabilities in the 'math_sum.mscgi' example script. These issues are due to a boundary condition error and a failure to properly sanitize user-supplied URI input.
 
An attacker could exploit the boundary condition issue to execute arbitrary code on the affected computer with the privileges of the user that started the affected application. The input validation issue could be leveraged to carry out cross-site scripting attacks against the affected computer.
 
These issues are reported to affect MyServer version 0.6.2, it is likely other versions are also affected.

http://www.example.com/cgi-bin/math_sum.mscgi?a=[AAA...x86...AAA]
 
Источник
www.exploit-db.com

Похожие темы