summaryrefslogtreecommitdiff
path: root/informationals/teso-i0003.txt
blob: 5d530abcb8c21750d9ba9c70af025004a05b3860 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
0003 2000/01/22  Remotely exploitable buffer overflow condition in webfind.exe
                 part of the WebsitePro Package (cgi-bin)

==== TESO Informational =======================================================
This piece of information is to be kept confidential.
===============================================================================

Description ..........: Remote buffer overflow
Date .................: 2000/01/22 19:06
Author ...............: Bawd
Publicity level ......: unknown
Affected .............: All WebsitePro HTTP servers running the webfind cgi
Type of entity .......: Daemon/Server
Type of discovery ....: bug
Severity/Importance ..: interesting
Found by .............: Bawd

Information ===================================================================

This buffer overflow allows a remote attacker to gain privileged access to
machines running the WebSite servers.

Filling the "Search For" case with more than 2000 characters will cause the cgi
to make an exception fault and overwrite the return address, which will
overwrite EIP.

"webfind.exe" is installed by default in the cgi-bin directory. Exploit is
coming later.

===============================================================================