[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2297Date: (C)2005-07-19   (M)2023-12-22


Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1014497
SECUNIA-16108
http://marc.info/?l=bugtraq&m=112146180532313&w=2
http://www.spidynamics.com/spilabs/advisories/sybaseEAserverOverflow.htm
http://www.sybase.com/detail?id=1036742

CPE    4
cpe:/a:sybase:easerver:5.1
cpe:/a:sybase:easerver:5.2
cpe:/a:sybase:easerver:5.0
cpe:/a:sybase:easerver:4.2.5
...

© SecPod Technologies