7.5
CVSSv2

CVE-2001-0476

Published: 27/06/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and previous versions allow remote malicious users to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

swsoft aspseek

swsoft aspseek 1.0

Exploits

source: wwwsecurityfocuscom/bid/2492/info A buffer overflow in ASPSeek versions 100 through to 103 allows for arbitrary code execution with the privileges of the web server The vulnerable script is scgi and the buffer overflow can be accessed by submitting an excessively long query string to the script (the variable tmpl, specifical ...