PT-2009-5967 · Alleycode · Alleycode Html Editor
Published
2009-10-16
·
Updated
2009-10-16
·
CVE-2009-3708
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Alleycode HTML Editor version 2.21
Description
A stack-based buffer overflow issue exists in the Meta Content Optimizer of Alleycode HTML Editor, allowing user-assisted remote attackers to execute arbitrary code. This can be achieved by providing a long value in either a
description or keyword META tag.Recommendations
For Alleycode HTML Editor version 2.21, consider disabling the Meta Content Optimizer feature until a patch is available to prevent potential exploitation. Restrict the input of
description and keyword META tags to minimize the risk of arbitrary code execution.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alleycode Html Editor