7.5
CVSSv2

CVE-2000-0846

Published: 14/11/2000 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in Darxite 0.4 and previous versions allows a remote malicious user to execute arbitrary commands via a long username or password.

Vulnerable Product Search on Vulmon Subscribe to Product

ashley montanaro darxite 0.4

Exploits

source: wwwsecurityfocuscom/bid/1598/info Darxite 04 does not do proper bounds checking on user-supplied data during the login process, relying on sprintf() to deliver the data into a 256 character buffer Therefore, it is possible for an attacker to supply arbitrary code for execution at the privilege level of the Darxite user /* ...