Microsoft BizTalk Server 2002 - HTTP Receiver Buffer Overflow

Related Vulnerabilities: CVE-2003-0117  
Publish Date: 30 Apr 2003
                							

                source: http://www.securityfocus.com/bid/7469/info

Microsoft BizTalk Server 2002 contains a boundary condition error that could allow a buffer to be overrun. Successful exploitation could allow arbitrary code execution in the security context of the IIS Server hosting the application.

It is important to note that the HTTP Receiver is an optional component and is not installed by default.

POST /Site/biztalkhttpreceive.dll?XXXX...(more than 250 chars) HTTP/1.0