Mini-SQL w3-msql Buffer Overflow...

- AV AC AU C I A
发布: 1999-12-27
修订: 2025-04-13

w3-msql is a cgi-program shipped with Mini-SQL which acts as a web interface for msql. There are a number of buffer overflow vulnerabilities in it with one proven to be exploitable. The exploitable buffer is the content-length field and the stack is overflowed inside of a scanf() call. As a result, it is possible to execute arbitrary code remotely as the uid of the webserver (usually nobody).

0%
暂无可用Exp或PoC
当前有0条受影响产品信息