vendor:
OmniHTTPD
by:
CoolICE
7.5
CVSS
HIGH
GET request buffer overflow
119
CWE
Product Name: OmniHTTPD
Affected Version From: <=V3.0a
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:omnicron:omnihttpd:3.0a
Platforms Tested: Windows
2004
OmniHTTPD GET Request Buffer Overflow
OmniHTTPD is affected by a GET request buffer overflow vulnerability. This issue occurs due to a failure of the application to properly validate string sizes when processing user input. An attacker could exploit this vulnerability to execute arbitrary code with the privileges of the affected web server.
Mitigation:
Upgrade to a version higher than V3.0a where the vulnerability has been patched.