vendor:
Spiceworks
by:
David Kennedy (ReL1K)
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Spiceworks
Affected Version From: 3.6
Affected Version To: 3.6
Patch Exists: YES
Related CWE: N/A
CPE: a:spiceworks:spiceworks
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 SP2 R2
2009
Spiceworks 3.6 Accept Parameter Overflow
Spiceworks 3.6 is vulnerable to a remote buffer overflow attack. By sending a specially crafted HTTP request with an overly long Accept parameter, an attacker can cause a denial of service condition. This vulnerability was discovered by SecureState R&D and was fixed in version 4.0 of Spiceworks.
Mitigation:
Upgrade to version 4.0 of Spiceworks.