WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
BID:4531
Info
WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
| Bugtraq ID: | 4531 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0595 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Mark Litchfield <[email protected]>. |
| Vulnerable: |
WebTrends Reporting Center for Windows 4.0 d |
| Not Vulnerable: | |
Discussion
WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
WebTrends Reporting Center is used to organize and present usage information for multiple server web environments. Reporting Center is available for Windows NT and 2000, Linux and Solaris.
An issue has been reported in WebTrends Reporting Center for Windows. An authenticated user of the system may be able to exploit a buffer overflow condition by submitting an oversized GET request. Exploitation may result in the execution of arbitrary code with SYSTEM privileges, or in a denial of service attack.
WebTrends Reporting Center is used to organize and present usage information for multiple server web environments. Reporting Center is available for Windows NT and 2000, Linux and Solaris.
An issue has been reported in WebTrends Reporting Center for Windows. An authenticated user of the system may be able to exploit a buffer overflow condition by submitting an oversized GET request. Exploitation may result in the execution of arbitrary code with SYSTEM privileges, or in a denial of service attack.
Exploit / POC
WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
The following proof of concept example has been provided:
http://targetmachine:1099/reports/(Long Char String)
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The following proof of concept example has been provided:
http://targetmachine:1099/reports/(Long Char String)
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebTrends Reporting Center GET Request Buffer Overflow Vulnerability
References:
References:
- Reporting Center Homepage (WebTrends)