Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0289

EPSS 4.31% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2002-0289

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Phusion Webserver超长URL引起缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Phusion Webserver是一个商业的HTTP服务器,它运行于Microsoft Windows平台。 Phusion Webserver存在一个缓冲区溢出漏洞。 Phusion Webserver没有对额外提交的数据进行充分的边界检查。所以一个远程攻击者提交一个超长的web请求将引起堆变量被攻击者提交的数据结构覆盖。 Microsoft Windows平台上的web服务器通常以SYSTEM权限运行,这将使攻击者可以完全控制目标主机。 这个缓冲区溢出问题同样能引起拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2002-0289

#POC DescriptionSource LinkShenlong Link
1Phusion WebServer 1.0 - 'URL' Remote Buffer Overflowhttps://github.com/alt3kx/CVE-2002-0289POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2002-0289

登录查看更多情报信息。

Same Patch Batch · n/a · 2002-05-03 · 218 CVEs total

CVE-2002-0271GNU Ada Compiler运行库泄露和临时文件创建漏洞
CVE-2002-0256Arescom Net DSL 1000远程登录拒绝服务漏洞
CVE-2002-0257MakeBid Auction Deluxe跨站脚本攻击(XSS)漏洞
CVE-2002-0258IceWarp Web Mail会话ID泄露漏洞
CVE-2002-0259InstantServers MiniPortal敏感文件纯文本存储漏洞
CVE-2002-0260InstantServers MiniPortal FTP远程登录缓冲区溢出漏洞
CVE-2002-0261InstantServers MiniPortal目录遍历漏洞
CVE-2002-0262Sybex E-Trainer软件相关路径过滤目录遍历漏洞
CVE-2002-0263EZNE.NET Ezboard 2000远程缓冲溢出漏洞
CVE-2002-0264Cooolsoft PowerFTP Server纯文本账户信息漏洞
CVE-2002-0266Thunderstone TEXIS路径泄露漏洞
CVE-2002-0268Identix BioLogon GINA认证绕过漏洞
CVE-2002-0269Microsoft Internet Explorer 安全漏洞
CVE-2002-0270Opera Content-Type HTML文件执行漏洞
CVE-2002-0285Outlook Express的附件回车/换行密封过滤绕过漏洞
CVE-2002-0282DCP-Portal WWW根目录绝对路径泄漏漏洞
CVE-2002-0283Windows XP服务拒绝(CPU消耗)漏洞
CVE-2002-0284Winamp路径名称泄露漏洞
CVE-2002-0281DCP-Portal用户信息跨站脚本执行漏洞
CVE-2002-0286Sitenews未认证用户添加漏洞

Showing top 20 of 218 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2002-0289

No comments yet


Leave a comment