Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3009

Опубликовано: 04 июн. 2007
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mbedthis_software:mbedthis_appweb_http_server:2.0.5-4:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.039
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.

EPSS

Процентиль: 88%
0.039
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other