6.4
CVSSv2

CVE-2005-1086

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote malicious users to execute arbitrary code via an HTTP request with a long User-Agent header.

Vulnerable Product Search on Vulmon Subscribe to Product

an an-httpd 1.42n

Exploits

source: wwwsecurityfocuscom/bid/13066/info AN HTTPD is reported prone to a remote buffer overflow vulnerability Specifically, the issue presents itself in 'cmdISDLL' which calls the 'GetEnvironmentStrings' function to copy environment variables into a finite sized process buffer The attacker can issue a malformed HTTP GET command inc ...