Vulnerability Description
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Swsoft | Aspseek | <= 1.0.3 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.htmlExploitVendor Advisory
- http://www.aspseek.org/changes.htmlPatch
- http://www.securityfocus.com/bid/2492ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6248
- http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.htmlExploitVendor Advisory
- http://www.aspseek.org/changes.htmlPatch
- http://www.securityfocus.com/bid/2492ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6248
FAQ
What is CVE-2001-0476?
CVE-2001-0476 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter...
How severe is CVE-2001-0476?
CVE-2001-0476 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0476?
Check the references section above for vendor advisories and patch information. Affected products include: Swsoft Aspseek.