MNOGoSearch Search.CGI TMPLT Buffer Overflow Vulnerability
BID:7866
Info
MNOGoSearch Search.CGI TMPLT Buffer Overflow Vulnerability
| Bugtraq ID: | 7866 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0437 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to pokleyzz <[email protected]>. |
| Vulnerable: |
mnoGoSearch mnoGoSearch 3.2.10 |
| Not Vulnerable: | |
Discussion
MNOGoSearch Search.CGI TMPLT Buffer Overflow Vulnerability
mnoGoSearch 'search.cgi' has been reported prone to a buffer overflow vulnerability.
The issue is a result of a lack of sufficient bounds checking performed on user-supplied URI parameters that are passed to the 'search.cgi' application.
It may be possible for an attacker to exploit this vulnerability and have arbitrary code executed in the context of the web-server process.
mnoGoSearch 'search.cgi' has been reported prone to a buffer overflow vulnerability.
The issue is a result of a lack of sufficient bounds checking performed on user-supplied URI parameters that are passed to the 'search.cgi' application.
It may be possible for an attacker to exploit this vulnerability and have arbitrary code executed in the context of the web-server process.
Exploit / POC
MNOGoSearch Search.CGI TMPLT Buffer Overflow Vulnerability
The following proof of concept exploit has been supplied:
The following proof of concept exploit has been supplied:
References
MNOGoSearch Search.CGI TMPLT Buffer Overflow Vulnerability
References:
References:
- mnogosearch 3.1.20 and 3.2.10 buffer overflow (pokleyzz
) - mnoGoSearch Homepage (mnoGoSearch)