O'Reilly WebSite 'webfind.exe'...

- AV AC AU C I A
发布: 2000-07-19
修订: 2025-04-13

O'Reilly WebSite Professional is a web server package distributed by O'Reilly & Associates. Certain versions of this web server (the entire 2.X version line) ship with a utility containing a remotely exploitable buffer overflow. The utility in question is a search engine utility titled 'webfind.exe'. This program takes unchecked user input from a provided search page which can result in a remote user launching arbitrary commands on the server itself. The variable in question which is overwritten is QUERY_STRING derived from user 'keywords' for their search.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息