Vector: | Remote |
Severity: | High |
Patch: | Patched |
Impact: |
Denial of Service (DoS) Remote Code Execution (RCE) |
Software: | WebAdmin 2.x |
A remote code execution vulnerability was found in WebAdmin USER Parameter.
Buffer overflow vulnerability exists in the handling of the "USER" parameter during login. An attacker can cause a buffer overflow by supplying an overly long, specially crafted string.
Solution:
For : Apply patch:
Links:
http://www.nextgenss.com/advisories/webadmin_altn.txt