Search:     Advanced search
server monitoring

iWS shtml overflow

Article ID: 10538
Last updated: 27 Jan, 2009
Views: 390
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

iWS shtml overflow

This script is Copyright (C) 2000 Renaud Deraison

FamilyGain a shell remotely
Plugin ID10538
Bugtraq ID1848
CVE IDCVE-2000-1077

Description:

It is possible to make the remote iPlanet web server execute
arbitrary code when requesting a too long .shtml file (with a name
longer than 800 chars and containing computer code).

An attacker may use this flaw to gain a shell on this host

Solution : Disable server side parsing of HTML page (Content Management -> Parse HTML)
Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
NSS Library SSLv2 Challenge Overflow     UW IMAP Mailbox Name Buffer Overflow