Search:     Advanced search
server monitoring

BadBlue ext.dll mfcisapicommand Parameter Remote Overflow

Article ID: 17241
Last updated: 27 Jan, 2009
Views: 382
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

BadBlue ext.dll mfcisapicommand Parameter Remote Overflow

This script is Copyright (C) 2005-2008 Tenable Network Security

FamilyGain a shell remotely
Plugin ID17241
Bugtraq ID12673
CVE IDCVE-2005-0595

Description:

Synopsis :

The remote web server is prone to buffer overflow attacks.

Description :

The remote host is running a version of BadBlue http server that has a
buffer overflow vulnerability in Ext.Dll, a module that handles http
requests. An unauthenticated remote attacker can leverage this
vulnerability by sending an HTTP request containing a
mfcisapicommand parameter with more than 250 chars to kill the web
server and possibly execute code remotely with Administrator rights.

See also :

http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0599.html

Solution :

Upgrade to BadBlue 2.60.0 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
OpenSSH 2.5.x - 2.9.x adv.option     NSS Library SSLv2 Challenge Overflow