Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2001-0476

EPSS 5.30% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2001-0476

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
SWSoft ASPSeek搜索引擎s.cgi远程溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Aspseek搜索引擎是用C/C++开发的搜索引擎,使用MySQL数据库存储数据。 它所带的一个CGI程序:s.cgi中存在多个缓冲区溢出漏洞,攻击者可能远程执行任意代码。 有问题的代码部分如下: 1. c.cpp: int search(char *exe, char *arg) { ==> if ((env = getenv("QUERY_STRING"))) { strcpy(query_string, env); .... } <== } 这里query_string的定义为: query_str
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2001-0476

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2001-0476

Please Login to view more intelligence information

Same Patch Batch · n/a · 2001-05-24 · 91 CVEs total

CVE-2001-0436DCForum 'AZ'字段远程命令执行漏洞
CVE-2001-0432Trend Micro Interscan Viruswall的CGI程序缓冲区溢出漏洞
CVE-2001-0426CDE dtsession缓冲区溢出漏洞
CVE-2001-0421Solaris FTP Core Dump文件泄漏用户口令散列漏洞
CVE-2001-0420Web TalkBack.cgi方式目录遍历漏洞
CVE-2001-0419Oracle Application Server ndwfn4.so远程缓冲区溢出漏洞
CVE-2001-0418NCM Content Management System content.pl输入验证漏洞
CVE-2001-0417Kerberos漏洞
CVE-2001-0424FreeBSD BubbleMon特权提升漏洞
CVE-2001-0435PGP分裂关键机制漏洞
CVE-2001-0433Savant缓冲区溢出漏洞
CVE-2001-0437DCForum 'AZ'字段远程命令执行漏洞
CVE-2001-0438Mac OS X漏洞
CVE-2001-0441SLRN超长头缓冲区溢出漏洞
CVE-2001-0443QVT/Net服务拒绝漏洞
CVE-2001-0446IBM WCS (WebSphere Commerce Suite)漏洞
CVE-2001-0447602Pro Lan Suite MS-Dos设备名称服务拒绝漏洞
CVE-2001-0448602Pro LAN SUITE Web配置服务器服务拒绝漏洞
CVE-2001-0450Transsoft FTP Broker目录遍历漏洞
CVE-2001-0451INDEXU权限许可和访问控制漏洞

Showing top 20 of 91 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2001-0476

No comments yet


Leave a comment