PT-2013-1994 · Sysax · Sysax Multi Server

Craig

·

Publicado

2013-01-31

·

Atualizado

2013-01-31

·

CVE-2012-6530

CVSS v2.0

7.1

Alta

VetorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sysax Multi Server versions prior to 5.52
Description The issue is a stack-based buffer overflow that occurs when HTTP is enabled. It allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request.
Recommendations For versions prior to 5.52, update to version 5.52 or later to resolve the issue. As a temporary workaround, consider disabling the HTTP functionality until a patch is available. Restrict access to the create folder permission to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-6530

Produtos afetados

Sysax Multi Server