vendor:
PlanetWeb
by:
tool bop.pl
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: PlanetWeb
Affected Version From: PlanetWeb v1.14
Affected Version To: PlanetWeb v1.14
Patch Exists: NO
Related CWE: N/A
CPE: a:planetdns:planetweb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Operating Systems
2002
PlanetWeb Buffer Overflow Vulnerability
PlanetWeb is a commercially available web server integrated with dynamic DNS services. It is distributed by PlanetDNS, and available for Microsoft Operating Systems. PlanetWeb does not properly handle long requests. Due to insufficient bounds checking, a long request sent to PlanetWeb may result in a buffer overflow. This could result in a denial of service, and has been reported as being exploitable to execute arbitrary code.
Mitigation:
Ensure that the web server is configured to handle requests of a certain length and that the length is not exceeded.