vendor:
PlanetWeb
by:
UkR-XblP / UkR security team
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: PlanetWeb
Affected Version From: PlanetWeb
Affected Version To: PlanetWeb
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2002
PlanetWeb Software perl exploit
PlanetWeb is vulnerable to a buffer overflow condition when handling GET requests of excessive length. Upon receiving a GET request containing a 1024 byte or greater URL, an exploitable buffer overflow occurs, which may result in the remote execution of arbitrary code within the context of the web server process.
Mitigation:
Upgrade to the latest version of PlanetWeb