vendor:
Simple Web Server
by:
xis_one, PsychoSpy
N/A
CVSS
N/A
Buffer Overflow
120
CWE
Product Name: Simple Web Server
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP/Win7
2013
Intrasrv 1.0 Buffer Overflow
This module exploits a boundary condition error in Intrasrv Simple Web Server 1.0. The web interface does not validate the boundaries of an HTTP request string prior to copying the data to an insufficiently large buffer. Successful exploitation leads to arbitrary remote code execution in the context of the application.
Mitigation:
Validate the boundaries of an HTTP request string prior to copying the data to an insufficiently large buffer.