vendor:
O'Reilly WebSite Professional
by:
Robert Horton
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: O'Reilly WebSite Professional
Affected Version From: 2.X version line
Affected Version To: 2.X version line
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2000
Buffer overrun in O’Reilly WebSite Professional’s webfind.exe
Certain versions of O'Reilly WebSite Professional's web server package ship with a utility called 'webfind.exe' that contains a remotely exploitable buffer overflow. This allows a remote user to execute arbitrary commands on the server by providing unchecked user input through a search page. The buffer overrun occurs in the 'QUERY_STRING' variable derived from the user's search keywords. The provided code is a proof of concept that launches the 'calc.exe' window on the server's machine.
Mitigation:
Apply the necessary patches or updates provided by O'Reilly & Associates. Alternatively, disable or remove the 'webfind.exe' utility if it is not required.