Description
NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer size through the Set username interface.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/45302 (ExploitDB-45302)
www.networkactiv.com/WebServer.html (Official Product Homepage)
www.networkactiv.com/Dev/ (Product Reference)
www.vulncheck.com/...rver-username-field-buffer-overflow-dos (VulnCheck Advisory: NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS)