7.5
CVSSv2

CVE-2001-0820

Published: 06/12/2001 Updated: 19/12/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflows in GazTek ghttpd 1.4 allows a remote malicious user to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.

Vulnerable Product Search on Vulmon Subscribe to Product

gaztek ghttp 1.4

Exploits

source: wwwsecurityfocuscom/bid/5960/info A buffer overflow has been reported in ghttpd which will allow arbitrary code to be executed with the privileges of the webserver The overflow occurs when the argument to a 'GET' request is of excessive length It is a stack-based overflow which may allow for attackers to overwrite stack variabl ...
source: wwwsecurityfocuscom/bid/2879/info ghttpd is a freely available, open source web server for Unix systems ghttpd supports CGI and is easy to configure and use A buffer overflow is known to exist in ghttp which will allow arbitrary code to be executed with the privileges of the webserver Proof-of-concept code has demonstrated th ...