website.oreilly.comConfirmation
http://website.oreilly.com/support/software/wspro25_releasenotes.txt CVE-2000-0622
OReilly Software WebSite Professional 2.3.18/2.4/2.4.9 - 'webfind.exe' Remote Buffer Overflow
Record summary
CVE-2000-0622 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOReilly Software WebSite Professional 2.3.18/2.4/2.4.9 - 'webfind.exe' Remote Buffer OverflowExploitDB exploitby Robert HortonNot analyzed1 file
References
520000719 O'Reilly WebSite Professional OverflowVendor advisory
http://www.nai.com/research/covert/advisories/043.asp 1487vdb entry
http://www.securityfocus.com/bid/1487 website-webfind-bo(4962)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/4962 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0622