header-logo
Suggest Exploit
vendor:
MyWebServer
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: MyWebServer
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:mywebserver:mywebserver:1.0.2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2002

MyWebServer Oversized HTTP Request Vulnerability

MyWebServer is an application and web server for Microsoft Windows operating systems. If an oversized HTTP request is received by MyWebServer, some content provided as a URL is included in the page generated. An attacker may construct a malicious URL, and entice a user of the site into following it. Injected content will then be rendered in the context of the vulnerable site.

Mitigation:

Upgrade to the latest version of MyWebServer
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/5470/info

MyWebServer is an application and web server for Microsoft Windows operating systems.

If an oversized HTTP request is received by MyWebServer, some content provided as a URL is included in the page generated. An attacker may construct a malicious URL, and entice a user of the site into following it. Injected content will then be rendered in the context of the vulnerable site.

The consequences of exploitation will be highly dependent on the nature of the hosted site.

This vulnerability has been reported in MyWebServer version 1.0.2. Earlier versions may share this vulnerability, this has not however been confirmed.

http://vuln_host/[223b_of_any_data]<font%20size=50>DEFACED<!--//--