Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SARG User-Agent Processing HTML Injection and Stack Buffer Overflow Vulnerabilities

SARG is prone to an HTML-injection vulnerability and a stack-based buffer-overflow vulnerability.

An attacker can exploit these issues to execute arbitrary HTML and attacker-supplied code in the context of the affected webserver, steal cookie-based authentication credentials, and cause a denial-of-service condition.

This issue affects SARG 2.2.3.1; prior versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus