Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

WWW-SQL Include Command Buffer Overflow Vulnerability

www-sql is reportedly vulnerable to a buffer overflow vulnerability in its include command implementation. This issue arises due to a failure of the affected application to properly handle user-supplied strings when copying them into finite stack-based buffers.

An attacker can leverage this issue to manipulate process memory; by supplying program code as well as a specially selected memory address an attacker gain control of the processes execution flow allowing for arbitrary code execution.







 

Privacy Statement
Copyright 2009, SecurityFocus