vendor:
Xitami Web Server
by:
Krystian Kloskowski (h07)
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Xitami Web Server
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: NO
Related CWE:
CPE: a:xitami:xitami_web_server:2.5
Platforms Tested: Windows XP SP2 Polish
2007
Xitami Web Server 2.5 (If-Modified-Since) 0day Remote Buffer Overflow Exploit
This is a remote buffer overflow exploit for Xitami Web Server 2.5. It takes advantage of the If-Modified-Since header to trigger the vulnerability and execute arbitrary code. The exploit was discovered by Krystian Kloskowski (h07) and tested on Xitami 2.5c2 on Windows XP SP2 Polish. The shellcode used in this exploit is the Windows Execute Command (calc) from metasploit.com.
Mitigation:
Apply the latest patch or update to Xitami Web Server to fix the buffer overflow vulnerability. Avoid using vulnerable versions of the software.