NGSSoftware Insight Security Research Advisory #NISR18072003 – The WiTango application server is vulnerable to a remote system buffer overrun. By passing a long cookie to Witango_UserReference, a remote attacker can overwrite the saved return address on the stack. As Witango is installed as LocalSystem, any arbitrary code execution will run as SYSTEM.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31402/NGSTango.txt
Source: https://packetstormsecurity.com/files/31402/NGSTango.txt.html