18013Third-party advisory
http://secunia.com/advisories/18013 CVE-2005-4270
Watchfire AppScan QA 5.0.x - Remote Code Execution
Record summary
CVE-2005-4270 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWatchfire AppScan QA 5.0.x - Remote Code ExecutionExploitDB exploitby Mariano NuñezNot analyzed1 file
References
8260Third-party advisory
http://securityreason.com/securityalert/260 1015362vdb entry
http://securitytracker.com/id?1015362 cybsec.com
http://www.cybsec.com/vuln/CYBSEC_Security_Advisory_AppScanQA_RemoteCodeExec.pdf 20051215 CYBSEC - Security Advisory: Watchfire AppScan QA Remote Code Executionmailing list
http://www.securityfocus.com/archive/1/419586/100/0/threaded 15873vdb entry
http://www.securityfocus.com/bid/15873 ADV-2005-2933vdb entry
http://www.vupen.com/english/advisories/2005/2933 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-4270