cybermind.user.stfunoob.com
http://cybermind.user.stfunoob.com/w48crash CVE-2007-1260
WebMod 0.48 - Content-Length Remote Buffer Overflow
Record summary
CVE-2007-1260 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execute arbitrary code via a long string in the Content-Length HTTP header.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBWebMod 0.48 - Content-Length Remote Buffer OverflowExploitDB exploitby cybermindNot analyzed1 file
Repository PoCs
GitHubthecybermind/w48crashRepository PoCby thecybermindStars: 1Not analyzed2 files
References
733834vdb entry
http://osvdb.org/33834 24346Third-party advisory
http://secunia.com/advisories/24346 22788vdb entry
http://www.securityfocus.com/bid/22788 webmod-contentlength-bo(32755)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/32755 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-1260 3395exploit
https://www.exploit-db.com/exploits/3395