Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netegrity SiteMinder Affiliate Agent远程堆溢出漏洞
Vulnerability Description
SiteMinder Affiliate Agent在相关站点的网络服务器上运行并提供单一登录,向相关站点用户提供个性化内容。 SiteMinder Affiliate Agent在处理COOKIE值"SMPROFILE"时缺少正确边界缓冲区检查,远程攻击者可以利用这个漏洞对程序进行基于堆的溢出,可能以进程权限执行任意指令。 SMPROFILE Cookie用于Affiliate agent来判断是否用户已经在站点注册,当"SMPROFILE"包含超长字符串的COOKIE值发送给服务器,可触发基于堆的溢出
CVSS Information
N/A
Vulnerability Type
N/A