Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2001-0476

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2001-0476
Last Modified 05 Sep 2008 04:24:12
Published 27 Jun 2001 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2001-0476

Summary

Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.

Vulnerable Systems

Application

  • Swsoft Aspseek 1.0

  • Swsoft Aspseek 1.0.3


References

XF - aspseek-scgi-bo

CONFIRM - http://www.aspseek.org/changes.html

BID - 2492

BUGTRAQ - 20010318 Aspseek Buffer Overflow


Last Updated: 27 May 2016 10:36:17