Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x57w-969p-qrv9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

EPSS

Процентиль: 89%
0.04463
Низкий

Дефекты

CWE-134

Связанные уязвимости

ubuntu
почти 18 лет назад

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

nvd
почти 18 лет назад

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

debian
почти 18 лет назад

Format string vulnerability in the ws_addarg function in webserver.c i ...

EPSS

Процентиль: 89%
0.04463
Низкий

Дефекты

CWE-134