Vulnerabilities > CVE-2000-0398 - Unspecified vulnerability in Rockliffe Mailsite 4.2.10
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Gain a shell remotely |
NASL id | ROCKLIFFE_MAILSITE_OVERFLOW.NASL |
description | The version of Rockliffe MailSite installed on the remote host is prone to a buffer overflow attack that can be triggered by a request like : GET /cgi-bin/wconsole.dll?AAAA....AAAA This may be of some use to an attacker to run arbitrary code on this system and/or crash it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 10421 |
published | 2000-05-25 |
reporter | This script is Copyright (C) 2000-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/10421 |
title | Rockliffe MailSite Management Agent wconsole.dll GET Request Overflow |
code |
|