TalentSoft Web+ Web Markup Language Buffer Overflow Vulnerability
BID:4282
Info
TalentSoft Web+ Web Markup Language Buffer Overflow Vulnerability
| Bugtraq ID: | 4282 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0450 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by NGSSoftware Insight Security Research <[email protected]>. |
| Vulnerable: |
TalentSoft Web+ Server 5.0 TalentSoft Web+ Server 4.6 |
| Not Vulnerable: | |
Discussion
TalentSoft Web+ Web Markup Language Buffer Overflow Vulnerability
TalentSoft Web+ is an environment for developing web-based client/server applications. It will run on Microsoft Windows 9x/NT/2000 and Unix operating systems.
An issue has been discovered in Web+ which could allow for users to execute arbitrary code with SYSTEM privileges.
Submitting a request for an unusually long .wml file could initiate a buffer overflow condition. This overflow could overwrite stack variables, including the return address, and be used to execute arbitrary code as the web server process. However, sending random data could cause the application to crash.
TalentSoft Web+ is an environment for developing web-based client/server applications. It will run on Microsoft Windows 9x/NT/2000 and Unix operating systems.
An issue has been discovered in Web+ which could allow for users to execute arbitrary code with SYSTEM privileges.
Submitting a request for an unusually long .wml file could initiate a buffer overflow condition. This overflow could overwrite stack variables, including the return address, and be used to execute arbitrary code as the web server process. However, sending random data could cause the application to crash.
References
TalentSoft Web+ Web Markup Language Buffer Overflow Vulnerability
References:
References:
- TalentSoft Homepage (TalentSoft)