← Vulnerability feed

Vulnerability record · CVE-2006-5112 · published 3 October 2006

CVE-2006-5112: NaviCOPA Web Server HTTP GET buffer overflow allows remote code execution

IIntervations · Navicopa Web Server

InterVations NaviCOPA Web Server 2.01 contains a buffer overflow triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an internet-facing service, so exposure is significant wherever the product is still deployed.

7.5 CVSS 2.0 High EPSS 67% · top 0.7%
7.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication, public exploit code exists, and EPSS is very high, though the product is old and not in CISA KEV.

What it is

InterVations NaviCOPA Web Server 2.01 contains a buffer overflow triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an internet-facing service, so exposure is significant wherever the product is still deployed.

Impact

Successful exploitation can give the attacker arbitrary code execution with the privileges of the web server process, leading to full compromise of the host. Even without reliable code execution, the overflow can crash the service, causing denial of service.

Attack surface

The flaw is reached over the network through the HTTP listener by sending a crafted, overly long GET request; no authentication or user interaction is required. The CVSS vector AV:N/AC:L/Au:N confirms a remotely reachable, low-complexity, unauthenticated path.

Exploitation

Public exploit code exists (SecurityFocus BID 20250 and Exploit-DB 2445 are tagged as exploit references), and EPSS is high at roughly 0.67 (99th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this dataset.

What to do

  • Patch or upgrade NaviCOPA Web Server to a fixed release if the vendor provides one; if no fix exists, retire or replace the product.
  • If the server must remain, restrict access to trusted networks and place it behind a reverse proxy or WAF that rejects oversized or malformed GET requests.
  • Enforce strict HTTP request length limits at the proxy or load balancer and drop requests exceeding normal URI/header sizes.
  • Run the web server as a low-privilege account in a segmented environment to limit the impact of code execution.
  • Monitor vendor and CERT/CC advisories for updated guidance, since the record does not name a fixed version.

Detection

  • Inspect web server and proxy logs for unusually long HTTP GET request lines or URIs that exceed normal length thresholds.
  • Alert on repeated malformed or oversized requests from a single source, which may indicate exploit attempts or scanning.
  • Monitor for unexpected process crashes or restarts of the NaviCOPA service, which can accompany buffer overflow attempts.
  • Use network IDS/IPS signatures for known NaviCOPA overflow exploit patterns where available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5112 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-5112), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.