Vulnerability record · CVE-2006-5112 · published 3 October 2006
CVE-2006-5112: NaviCOPA Web Server HTTP GET buffer overflow allows remote code execution
IIntervations · Navicopa Web Server
InterVations NaviCOPA Web Server 2.01 contains a buffer overflow triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an internet-facing service, so exposure is significant wherever the product is still deployed.
Description
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, public exploit code exists, and EPSS is very high, though the product is old and not in CISA KEV.
What it is
InterVations NaviCOPA Web Server 2.01 contains a buffer overflow triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to corrupt memory and potentially execute arbitrary code on the server. The flaw is in an internet-facing service, so exposure is significant wherever the product is still deployed.
Impact
Successful exploitation can give the attacker arbitrary code execution with the privileges of the web server process, leading to full compromise of the host. Even without reliable code execution, the overflow can crash the service, causing denial of service.
Attack surface
The flaw is reached over the network through the HTTP listener by sending a crafted, overly long GET request; no authentication or user interaction is required. The CVSS vector AV:N/AC:L/Au:N confirms a remotely reachable, low-complexity, unauthenticated path.
Exploitation
Public exploit code exists (SecurityFocus BID 20250 and Exploit-DB 2445 are tagged as exploit references), and EPSS is high at roughly 0.67 (99th percentile), but the CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record in this dataset.
What to do
- Patch or upgrade NaviCOPA Web Server to a fixed release if the vendor provides one; if no fix exists, retire or replace the product.
- If the server must remain, restrict access to trusted networks and place it behind a reverse proxy or WAF that rejects oversized or malformed GET requests.
- Enforce strict HTTP request length limits at the proxy or load balancer and drop requests exceeding normal URI/header sizes.
- Run the web server as a low-privilege account in a segmented environment to limit the impact of code execution.
- Monitor vendor and CERT/CC advisories for updated guidance, since the record does not name a fixed version.
Detection
- Inspect web server and proxy logs for unusually long HTTP GET request lines or URIs that exceed normal length thresholds.
- Alert on repeated malformed or oversized requests from a single source, which may indicate exploit attempts or scanning.
- Monitor for unexpected process crashes or restarts of the NaviCOPA service, which can accompany buffer overflow attempts.
- Use network IDS/IPS signatures for known NaviCOPA overflow exploit patterns where available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5112 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5112), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.