Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IA WebMail Server超长GET请求远程缓冲区溢出漏洞
Vulnerability Description
IA WebMail Server是一款强大的基于WEB的邮件服务程序。 IA WebMail Server对用户提交的HTTP GET请求缺少充分过滤,远程攻击者可以利用这个漏洞进行缓冲区溢出攻击,可能以Webmail进程权限在系统上执行任意指令。 如果攻击者提交超过1044字节的HTTP GET请求,由于lstrcpya()函数缺少充分的边界缓冲区检查,可触发缓冲区溢出,覆盖堆栈中的返回地址,精心构建提交数据可能以Webmail进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A