vendor:
Ultra MiniHTTPd
by:
jollymongrel
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Ultra MiniHTTPd
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: CVE-2013-5019
CPE: a:vector:ultra_minihttpd:1.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2018
Ultra MiniHTTPd 1.2 – ‘GET’ Remote Stack Buffer Overflow
A buffer overflow vulnerability exists in Ultra MiniHTTPd 1.2 due to improper bounds checking of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application. This vulnerability can be exploited remotely via a specially crafted HTTP GET request.
Mitigation:
Upgrade to the latest version of Ultra MiniHTTPd 1.2