vendor:
HTTPd
by:
Xtremist
7.5
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: HTTPd
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: YES
Related CWE: N/A
CPE: a:ncsa:httpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: *nix systems
2002
NCSA HTTPd Buffer Overflow Vulnerability
NCSA HTTPd versions 1.3 and earlier are prone to an exploitable buffer overflow(in the username field) which will allow malicious remote users to execute arbitrary code with the privileges of the webserver process. Successful exploitation of this vulnerability will allow a remote attacker to gain local access to the host.
Mitigation:
Upgrade to the latest version of NCSA HTTPd