vendor:
IIS ISAPI w3who.dll
by:
hdm
N/A
CVSS
N/A
Stack Buffer Overflow
119
CWE
Product Name: IIS ISAPI w3who.dll
Affected Version From: Windows 2000
Affected Version To: Windows XP (SP2)
Patch Exists: NO
Related CWE: CVE-2004-1134
CPE: None
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=15910, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/isapi/w3who_query, https://www.infosecmatter.com/nessus-plugin-library/?id=152139, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000, Windows XP (SP2)
2004
Microsoft IIS ISAPI w3who.dll Query String Overflow
This module exploits a stack buffer overflow in the w3who.dll ISAPI application. This vulnerability was discovered Nicolas Gregoire and this code has been successfully tested against Windows 2000 and Windows XP (SP2). When exploiting Windows XP, the payload must call RevertToSelf before it will be able to spawn a command shell.
Mitigation:
No known mitigation or remediation for this vulnerability