PT-2010-1578 · Httpdx · Httpdx

Published

2010-04-20

·

Updated

2010-06-07

·

CVE-2009-4769

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions httpdx versions 1.4 through 1.5
Description The issue allows remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled. Additionally, remote authenticated users can execute arbitrary code via format string specifiers in a PWD command to the FTP server component.
Recommendations For versions 1.4 through 1.5, consider disabling the logging feature in the HTTP server component and restricting access to the FTP server component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4769

Affected Products

Httpdx