Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4769

Опубликовано: 20 апр. 2010
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jasper:httpdx:1.4:*:*:*:*:*:*:*
cpe:2.3:a:jasper:httpdx:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:jasper:httpdx:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:jasper:httpdx:1.4.6b:*:*:*:*:*:*:*
cpe:2.3:a:jasper:httpdx:1.5:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.62136
Средний

9.3 Critical

CVSS2

Дефекты

CWE-134

Связанные уязвимости

github
почти 4 года назад

Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.

EPSS

Процентиль: 98%
0.62136
Средний

9.3 Critical

CVSS2

Дефекты

CWE-134