|
|
|
|
| |
Credit:
The information has been provided by Luigi Auriemma.
|
| |
Vulnerable Systems:
* 3S - Smart Software Solutions GmbH CoDeSys 3.4 SP4 Patch 2 and prior
An attacker may leverage these issues to cause a denial-of-service condition or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Successfully exploiting the cross-site scripting issue may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
CVE-2011-5007:Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.
CVE-2011-5008:Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.
CVE Information:
CVE-2011-5007
CVE-2011-5008
Disclosure Timeline:
Published:November 29 2011
Updated: November 16 2012
|
|
|
|
|