Exploit published for buffer overflow in BEA WebLogic - Calendar Of Updates(情報元のブックマーク数)

WebLogicのバッファオーバフローな脆弱性をつくExploitが出ているそうです。

それもPOSTでいけるの?!

A hacker known as KingCope has discovered a potential buffer overflow in BEA WebLogic which can at least trigger system crashes, but may also be exploited to remotely inject and execute arbitrary code. The flaw is caused by Apache Connector which appears not to check certain POST requests sufficiently.

According to comments the published exploit is "broken" and doesn't function properly. Nevertheless, security providers FrSIRT and Secunia have rated the vulnerability as critical and highly critical respectively. According to Secunia, versions 5 to 10 are affected. No patch has so far become available.

screenshot