Vulnerabilities > CVE-2006-4654 - Remote Format String vulnerability in EFS Software Easy Address Book web Server 1.2
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Easy Address Book Web Server 1.2 Remote Format String Vulnerability. CVE-2006-4654. Remote exploit for windows platform |
id | EDB-ID:28489 |
last seen | 2016-02-03 |
modified | 2006-09-04 |
published | 2006-09-04 |
reporter | Revnic Vasile |
source | https://www.exploit-db.com/download/28489/ |
title | Easy Address Book Web Server 1.2 - Remote Format String Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | EABWS_ARG_FORMAT_STRING.NASL |
description | It appears that the remote web server is affected by a remote format string issue. Using a specially crafted URL containing a format string specifier, an unauthenticated, remote attacker can crash the affected application and possibly execute arbitrary code on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22305 |
published | 2006-09-05 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22305 |
title | Easy Address Book Web Server Query Remote Format String |
code |
|