vendor:
SecurityGateway
by:
securfrog
9
CVSS
CRITICAL
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: SecurityGateway
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
SecurityGateway 1.0.1 Remote Buffer Overflow ( username)
SecurityGateway open port 4000 for remote administration/managment, EIP get owned when the username field is filled with 720 chars. Replace http://127.0.0.1:4000/ with your remote host. Use LWP::UserAgent to send a POST request with a payload of 236 'a' characters, 480 'b' characters, and 4 'c' characters to the SecurityGateway.dll page.
Mitigation:
Ensure that the username field is not filled with more than the maximum allowed characters.