CVE-2010-20112
Last modified
CVE-2010-20112 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured Exception Handler (SEH). EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured Exception Handler (SEH). Additionally, malformed parameter names followed by an equals sign may result in unintended control flow behavior. This vulnerability is exposed through IIS and affects legacy Windows deployments
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2010-20112?
How severe is CVE-2010-20112?
How do I fix CVE-2010-20112?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-20107A stack-based buffer overflow exists in FTP Synchronizer Pro…8.5
- CVE-2010-20108FTPPad <= 1.2.0 contains a stack-based buffer overflow vulne…8.4
- CVE-2010-20109Barracuda products, confirmed in Spam & Virus Firewall, SSL …8.7
- CVE-2010-2011Microsoft Dynamics GP uses a substitution cipher to encrypt …
- CVE-2010-20110Rejected reason: This CVE has the been REJECTED and will not…
- CVE-2010-20111Digital Music Pad v8.2.3.3.4 contains a stack-based buffer o…8.4
- CVE-2010-20113EasyFTP Server 1.7.0.11 and earlier contains a stack-based b…9.8
- CVE-2010-20114VariCAD EN up to and including version 2010-2.05 is vulnerab…8.4
- CVE-2010-20115Arcane Software’s Vermillion FTP Daemon (vftpd) versions up …9.3
- CVE-2010-20116Rejected reason: This CVE has the been REJECTED and will not…
- CVE-2010-20117Rejected reason: This CVE has the been REJECTED and will not…
- CVE-2010-20118Rejected reason: This CVE has the been REJECTED and will not…
Are you affected by CVE-2010-20112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
