vendor:
Phusion Webserver
by:
Alex Hernandez
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Phusion Webserver
Affected Version From: Phusion Webserver v1.0
Affected Version To: Phusion Webserver v1.0
Patch Exists: NO
Related CWE:
CPE: a:phusion:webserver:1.0
Platforms Tested: Windows 9x/NT/2000
2002
Phusion Webserver Remote Code Execution
Phusion Webserver does not perform sufficient bounds checking of externally supplied data, allowing a remote attacker to submit an excessively long web request which may cause stack variables to be overwritten with attacker-supplied instructions. This can lead to remote code execution and potential compromise of the host.
Mitigation:
Apply the latest patches or updates from the vendor. If a patch is not available, consider using an alternative web server software.