Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lownoise

#35645of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2004-1864
7.5
2004-08-27
Ipswitch · Ipswitch Whatsup Gold · CVE-2004-0798
**Name of the Vulnerable Software and Affected Versions** Ipswitch WhatsUp Gold versions prior to 8.03 Hotfix 1 **Description** The issue is related to a buffer overflow in the maincfgret.cgi script, allowing remote attackers to execute arbitrary code via a long `instancename` parameter. **Recommendations** For Ipswitch WhatsUp Gold versions prior to 8.03 Hotfix 1, update to version 8.03 Hotfix 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the maincfgret.cgi script to minimize the risk of exploitation. Avoid using long `instancename` parameters in the affected script until the issue is resolved.