PT-2009-5935 · Httpdx · Httpdx Web Server
Publicado
2009-10-11
·
Atualizado
2017-09-19
·
CVE-2009-3663
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
httpdx Web Server version 1.4
Description
The issue is related to a format string vulnerability in the h readrequest function. This vulnerability can be exploited by remote attackers who send format string specifiers in the Host header, potentially causing a denial of service or allowing the execution of arbitrary code.
Recommendations
For httpdx Web Server version 1.4, consider disabling the h readrequest function until a patch is available to prevent potential exploitation. Restrict access to the httpdx Web Server to minimize the risk of denial of service or arbitrary code execution.
Exploit
Correção
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Httpdx Web Server