5
CVSSv2

CVE-2000-0908

Published: 19/12/2000 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

BrowseGate 2.80 allows remote malicious users to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

netcplus browsegate 2.80

Exploits

source: wwwsecurityfocuscom/bid/1702/info NetcPlus BrowseGate 280 will crash as the result of an invalid read error if a number of character strings consisting of 8 KB are inserted into GET request arguments through port 80 For example: GET / HTTP/10<cr> Authorization: Basic(8 KB string of characters)<cr> From: email@addr ...