PT-2009-5967 · Alleycode · Alleycode Html Editor
Publicado
2009-10-16
·
Atualizado
2009-10-16
·
CVE-2009-3708
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Alleycode HTML Editor version 2.21
Description
A stack-based buffer overflow issue exists in the Meta Content Optimizer of Alleycode HTML Editor, allowing user-assisted remote attackers to execute arbitrary code. This can be achieved by providing a long value in either a
description or keyword META tag.Recommendations
For Alleycode HTML Editor version 2.21, consider disabling the Meta Content Optimizer feature until a patch is available to prevent potential exploitation. Restrict the input of
description and keyword META tags to minimize the risk of arbitrary code execution.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alleycode Html Editor