First published: Fri May 05 2000(Updated: )
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin DNewsWeb | =5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0423 has a high severity rating due to its potential for remote command execution.
To fix CVE-2000-0423, update the Netwin DNEWS software to a version that addresses this buffer overflow vulnerability.
CVE-2000-0423 specifically affects version 5.3 of the Netwin DNEWS software.
Yes, CVE-2000-0423 can be exploited remotely due to the vulnerabilities in the CGI program.
Exploiting CVE-2000-0423 can allow attackers to execute arbitrary commands on the affected system.