CVE-2005-4270

Watchfire AppScan QA 5.0.609 and 5.0.134 - Remote Code Execution via Long Realm Field in WWW-Authenticate Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-4270. PoCs published by Mariano Nuñez.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Watchfire AppScan QA by serving a malicious 401 response with embedded shellcode. The PoC sets up a fake web server that triggers the exploit when a request for the 'admin' resource is detected.

Description

Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mariano Nuñez · perlremotewindows
https://www.exploit-db.com/exploits/1374

This exploit targets a buffer overflow vulnerability in Watchfire AppScan QA by serving a malicious 401 response with embedded shellcode. The PoC sets up a fake web server that triggers the exploit when a request for the 'admin' resource is detected.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Watchfire AppScan QA (Windows 2000 Server SP4)
No auth needed
Prerequisites: Victim must scan the malicious server with AppScan QA · Target must be running Windows 2000 Server SP4
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15873
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18013
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/419586/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015362
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/260
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2933

Scores

EPSS 0.0549
EPSS Percentile 91.8%

Details

Status published
Products (2)
watchfire/appscan_qa 5.0.134
watchfire/appscan_qa 5.0.609
Published Dec 15, 2005
Tracked Since Feb 18, 2026