PT-2003-1855 · Foxweb · Foxweb
Published
2003-09-12
·
Updated
2008-09-10
·
CVE-2003-0762
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Foxweb version 2.5
Description:
The issue is related to a buffer overflow in the foxweb.dll and foxweb.exe components. This can be exploited by remote attackers who send a long URL, specifically targeting the PATH INFO value, allowing them to execute arbitrary code.
Recommendations:
For Foxweb version 2.5, consider restricting access to the foxweb.dll and foxweb.exe components until a patch is available. As a temporary workaround, limit the length of URLs that can be processed to prevent exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Foxweb