vendor:
Static HTTP Server
by:
Jacob Holcomb
7.5
CVSS
HIGH
SEH Overflow
CWE
Product Name: Static HTTP Server
Affected Version From: Static HTTP Server v1.0
Affected Version To: Static HTTP Server v1.0
Patch Exists: NO
Related CWE: Pending
CPE:
Platforms Tested: Windows XP SP2
2013
Static HTTP Server SEH Overflow – HTTP Config – http_tiplist
Multiple HTTP commands and headers are vulnerable to overflows and trigger an exception, but I was unable to control the SEH handler with anything but configuration options in the http.ini.