PT-2006-6523 · Essentia · Essentia Web Server

Corryl

·

Published

2006-11-10

·

Updated

2018-10-17

·

CVE-2006-5850

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Essentia Web Server version 2.15
Description A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request to API endpoints such as "/api/v1/login" or "/users/{id}". This can be achieved by manipulating the uri variable.
Recommendations For Essentia Web Server version 2.15, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to API endpoints that may be vulnerable to buffer overflow attacks until a patch is available. Avoid using long URIs in requests to the server until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5850

Affected Products

Essentia Web Server