Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CA XOsoft多个远程缓冲区溢出漏洞
Vulnerability Description
CA XOsoft产品的/ws_man/xosoapapi.asmx SOAP端点在向服务器提交畸形请求时缺少边界检查,/entry_point.aspx服务将用户提供的字符串拷贝到了栈上固定长度的缓冲区。远程攻击者可以通过向服务器提交畸形请求触发缓冲区溢出,导致以当前服务的权限执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A