Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-1946

Опубликовано: 19 апр. 2004
Источник: nvd
CVSS2: 4.6
EPSS Низкий

Описание

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cherokee:cherokee_httpd:0.4.16:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00084
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

debian
больше 21 года назад

Format string vulnerability in the PRINT_ERROR function in common.c fo ...

github
больше 3 лет назад

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

EPSS

Процентиль: 25%
0.00084
Низкий

4.6 Medium

CVSS2

Дефекты

NVD-CWE-Other