Unchecked Buffer In WebBBS May Run Arbitrary Code
Reported June 19 by
Delphis Consulting Plc

VERSIONS AFFECTED
WebBBS v1.15

DESCRIPTION

An unchecked buffer condition exists in the WebBBS software, where long parameter strings sent with GET commands can allow arbitrary code to execute on the system.

By sending a string that is 549 characters in length (including the EIP address) an overflow will occur overwriting the EIP register, thereby allowing arbitrary code to run on the server 

VENDOR RESPONSE

The author has released a new version of the software. Be sure to upgrade to v1.17 as soon as possible. WebBBS Home Page

CREDITS
Discovered and reported by Delphis Consulting Plc