Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5265

Опубликовано: 08 окт. 2007
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) password fields when accessing certain "restricted zones", which are not properly handled by the (a) processWebHeader and (b) filterWebRequest functions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dawnoftime:dawn_of_time:*:*:*:*:*:*:*:*
Версия до 1.69s_beta4 (включая)

EPSS

Процентиль: 94%
0.12303
Средний

7.5 High

CVSS2

Дефекты

CWE-134

Связанные уязвимости

github
почти 4 года назад

Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) password fields when accessing certain "restricted zones", which are not properly handled by the (a) processWebHeader and (b) filterWebRequest functions.

EPSS

Процентиль: 94%
0.12303
Средний

7.5 High

CVSS2

Дефекты

CWE-134