Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pqg-mc4c-xrv2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

EPSS

Процентиль: 85%
0.02534
Низкий

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

EPSS

Процентиль: 85%
0.02534
Низкий

Дефекты

CWE-415