CVE-2009-4873

Rhinosoft Serv-u - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Megumi Yanagishita · c++remotewindows
https://www.exploit-db.com/exploits/9800
exploitdb WORKING POC VERIFIED
by Nikolas Rangos · textremotewindows
https://www.exploit-db.com/exploits/9966

Scores

EPSS 0.6024
EPSS Percentile 98.3%

Details

CWE
CWE-119
Status published
Products (1)
rhinosoft/serv-u 9.0.0.5
Published May 26, 2010
Tracked Since Feb 18, 2026