20010822 AOLserver 3.0 vulnerabilitymailing list
http://archives.neohapsis.com/archives/bugtraq/2001-08/0325.html CVE-2001-1067
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (1)
Record summary
CVE-2001-1067 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBAOLServer 3 - 'Authentication String' Remote Buffer Overflow (1)ExploitDB exploitby Nate HaggardNot analyzed1 file
ExploitDBAOLServer 3 - 'Authentication String' Remote Buffer Overflow (2)ExploitDB exploitby qitest1Not analyzed1 file
References
520010906 AOLserver exploit codemailing list
http://www.securityfocus.com/archive/1/213041 3230vdb entry
http://www.securityfocus.com/bid/3230 aolserver-long-password-dos(7030)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7030 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-1067