SmartDesk WebSuite缓冲区溢出漏洞

SmartDesk WebSuite缓冲区溢出漏洞

漏洞ID 1105461 漏洞类型 缓冲区溢出
发布时间 1999-05-25 更新时间 2005-05-02
图片[1]-SmartDesk WebSuite缓冲区溢出漏洞-安全小百科CVE编号 CVE-1999-0928
图片[2]-SmartDesk WebSuite缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-199905-042
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/19221
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199905-042
|漏洞详情
SmartDeskWebSuite中存在缓冲区溢出漏洞。远程攻击者借助长URL导致拒绝服务。
|漏洞EXP
source: http://www.securityfocus.com/bid/278/info

A buffer overflow vulnerability in SmartDesk WebSuite 2.1 allows malicious remote users to crash the server, and may at worst allow them to execute arbitrary code.

WebSuite 2.1 will crash when the filename requested is overly long. Test showed the filename length that crashed the server varied from 250 to over 2,000 bytes long. 

On Windows 98, append 150 to 1,000+ characters to the URL.

On Windows NT, append 250 to 2,000+ characters to the URL.

example:

http://hostname/00000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000
|参考资料

来源:BID
名称:278
链接:http://www.securityfocus.com/bid/278

相关推荐: PHPCatalog ID Parameter SQL Injection Vulnerability

PHPCatalog ID Parameter SQL Injection Vulnerability 漏洞ID 1099132 漏洞类型 Input Validation Error 发布时间 2003-12-29 更新时间 2003-12-29 CVE编号…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享