vendor:
Windows Light HTTPD v0.1
by:
Jacob Holcomb/Gimppy042
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: Windows Light HTTPD v0.1
Affected Version From: Windows Light HTTPD v0.1
Affected Version To: Windows Light HTTPD v0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2
2013
Windows Light HTTPD v0.1 HTTP GET Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in Windows Light HTTPD v0.1. By sending a specially crafted HTTP GET request, an attacker can overflow the buffer and execute arbitrary code on the target system. The exploit uses a payload that spawns a shell bind TCP connection on port 1337. The vulnerability was discovered and reported by Jacob Holcomb/Gimppy042 on 24th April, 2013. The affected software can be downloaded from the software vendor's website at http://sourceforge.net/projects/lhttpd/?source=navbar. More information about the exploit can be found in the advisory at http://infosec42.blogspot.com/.
Mitigation:
Apply the latest security patches or updates provided by the software vendor.