Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

O'Reilly WebSite 'webfind.exe' Buffer Overflow Vulnerability

O'Reilly WebSite Professional is a web server package distributed by O'Reilly & Associates. Certain versions of this web server (the entire 2.X version line) ship with a utility containing a remotely exploitable buffer overflow. The utility in question is a search engine utility titled 'webfind.exe'. This program takes unchecked user input from a provided search page which can result in a remote user launching arbitrary commands on the server itself. The variable in question which is overwritten is QUERY_STRING derived from user 'keywords' for their search.







 

Privacy Statement
Copyright 2009, SecurityFocus