CGI_VW_FTPSAVE_CSP_EXPLOIT
Publish date: 04 de febrero de 2011
Gravedad: High
Fecha recomendada: 04 de febrero de 2011
Descripción
This vulnerability allows remote users to execute arbitrary code on the server and obtain system level privileges on the server. The vulnerability is reportedly due to a buffer overflow in two administrative programs: FtpSaveCSP.dll and FtpSaveCVP.dll. If long strings are included in a certain configuration parameter, the vulnerability will be triggered when the remote user views following dll(s):
http://server/interscan/cgi-bin/FtpSaveCSP.dll
http://server/interscan/cgi-bin/FtpSaveCVP.dll
Revelación de la información
Download the latest NVW pattern file from this site:
http://www.trendmicro.com/download/product.asp?productid=45
Software y versión afectados
- InterScan VirusWall for Windows NT 3.51J build 1321 Japanese
- InterScan VirusWall for Windows NT 3.51 build 1321 English