vendor:
Netscape Enterprise Server
by:
fyodor@relaygroup.com
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Netscape Enterprise Server
Affected Version From: Netscape Enterprise Server 4.0
Affected Version To: Netscape Enterprise Server 4.0
Patch Exists: NO
Related CWE:
CPE: a:netscape:enterprise_server:4.0
Platforms Tested: SunOS 5.7
Unknown
Remote sploit for Netscape Enterprise Server 4.0/sparc/SunOS 5.7
This is a remote exploit for Netscape Enterprise Server 4.0 on the sparc architecture running SunOS 5.7. The exploit allows an attacker to execute arbitrary commands on the target system. The attacker needs to provide a command line argument that will be executed on the target system. The exploit takes advantage of a vulnerability in the server to inject and execute the provided command. The command is encoded to replace bad characters. The exploit uses a shellcode to execute the command.
Mitigation:
Upgrade to a patched version of Netscape Enterprise Server or replace it with a more secure alternative. Be cautious of accepting and executing commands from untrusted sources.