📄 3468.txt
字号:
Rule:--Sid:3468--Summary:This event is generated when an attempt is made to access the cgi scriptmath_sum.mscgi.--Impact:Serious. Code execution is possible. Cross site scripting is alsofeasible.--Detailed Information:MyServer is a server used for various methods of file sharing. Due to aprogramming error a buffer overflow condition exists in the application.Specifically the script math_sum.mscgi does not correctly sanitize userinput.--Affected Systems: MyServer 0.6.2 and prior--Attack Scenarios:An attacker can supply data of their choosing to the math_sum.mscgiscript to cause the overflow.--Ease of Attack:Simple. No exploit software required.--False Positives:None known.--False Negatives:None known.--Corrective Action:Ensure the system is using an up to date version of the software.--Contributors:Sourcefire Research TeamAlex Kirk <akirk@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -