Mercantec Softcart CGI Buffer Overflow Vulnerability
BID:10926
Info
Mercantec Softcart CGI Buffer Overflow Vulnerability
| Bugtraq ID: | 10926 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2004 12:00AM |
| Updated: | Aug 12 2004 12:00AM |
| Credit: | Discovery is credited to trew and skape. |
| Vulnerable: |
Mercantec SoftCart 4.0 0.b |
| Not Vulnerable: | |
Discussion
Mercantec Softcart CGI Buffer Overflow Vulnerability
The Mercantec SoftCart CGI executable is prone to a remotely exploitable buffer overflow. This may allow code execution in the context of the hosting Web server.
This issue is known to affect version 4.00b on BSDi/4.3 systems, other releases may also be affected.
The Mercantec SoftCart CGI executable is prone to a remotely exploitable buffer overflow. This may allow code execution in the context of the hosting Web server.
This issue is known to affect version 4.00b on BSDi/4.3 systems, other releases may also be affected.
Exploit / POC
Mercantec Softcart CGI Buffer Overflow Vulnerability
An exploit has been released for the Metasploit Framework:
An exploit has been released for the Metasploit Framework:
Solution / Fix
Mercantec Softcart CGI Buffer Overflow Vulnerability
Solution:
The vendor has developed a patch to address this issue. Users can also address this issue by upgrading to a newer version of Mercantec Softcart. Please contact the vendor <[email protected]> to obtain the patch or to upgrade to a fixed version.
Solution:
The vendor has developed a patch to address this issue. Users can also address this issue by upgrading to a newer version of Mercantec Softcart. Please contact the vendor <[email protected]> to obtain the patch or to upgrade to a fixed version.
References
Mercantec Softcart CGI Buffer Overflow Vulnerability
References:
References:
- Mercantec SoftCart CGI overflow (Metasploit Framework)
- Vendor Homepage (Mercantec)