PT-2013-1994 · Sysax · Sysax Multi Server
Craig
·
Publicado
2013-01-31
·
Atualizado
2013-01-31
·
CVE-2012-6530
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sysax Multi Server versions prior to 5.52
Description
The issue is a stack-based buffer overflow that occurs when HTTP is enabled. It allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request.
Recommendations
For versions prior to 5.52, update to version 5.52 or later to resolve the issue. As a temporary workaround, consider disabling the HTTP functionality until a patch is available. Restrict access to the create folder permission to minimize the risk of exploitation.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sysax Multi Server