Moby NetSuite POST Handler缓冲区溢出漏洞

Moby NetSuite POST Handler缓冲区溢出漏洞

漏洞ID 1107118 漏洞类型 缓冲区溢出
发布时间 2002-11-29 更新时间 2002-12-31
图片[1]-Moby NetSuite POST Handler缓冲区溢出漏洞-安全小百科CVE编号 CVE-2002-2258
图片[2]-Moby NetSuite POST Handler缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200212-300
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/22053
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-300
|漏洞详情
MobyNetSuite存在漏洞。远程攻击者借助具有Content-Length头中(1)超大整数或者(2)non-numeric值的HTTPPOST请求导致服务拒绝(崩溃),该漏洞在atoi函数调用失败后导致访问冲突。
|漏洞EXP
source: http://www.securityfocus.com/bid/6277/info

A buffer overflow vulnerability has been reported for Moby NetSuite that may result in a denial of service condition. Reportedly, it is possible to cause NetSuite to crash when a malformed POST request is received. 

An attacker can exploit this vulnerability by issuing a malformed POST request. When NetSuite attempts to service the malformed POST request, it will crash resulting in a denial of service. Restarting the service is neccessary to restore functionality.

POST /cgi-bin/test.cgi HTTP/1.0
Content-Length: 111111111111111111111111111
|参考资料

来源:XF
名称:netsuite-post-contentlength-bo(10725)
链接:http://xforce.iss.net/xforce/xfdb/10725
来源:BID
名称:6277
链接:http://www.securityfocus.com/bid/6277
来源:BUGTRAQ
名称:20021128MobyNetSuitePOSTDenialofServiceVulnerability
链接:http://archives.neohapsis.com/archives/bugtraq/2002-11/0364.html

相关推荐: ECS K7S5A Boot Menu Access Vulnerability

ECS K7S5A Boot Menu Access Vulnerability 漏洞ID 1102048 漏洞类型 Design Error 发布时间 2002-05-28 更新时间 2002-05-28 CVE编号 N/A CNNVD-ID N/A 漏洞平…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享