Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/4426 | exploit |
http://www.securityfocus.com/bid/25715 | vdb entry |
http://www.vupen.com/english/advisories/2007/3226 | vdb entry |
http://www.sybsecurity.com/advisors/SYBSEC-ADV01-Airsensor_M520_HTTPD_Remote_Preauth_Denial_Of_Service_and_Buffer_Overflow_PoC | exploit vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36691 | vdb entry |
http://secunia.com/advisories/26869 | exploit third party advisory vendor advisory |