Vulnerabilities > CVE-2007-3009 - Unspecified vulnerability in Mbedthis Software Mbedthis Appweb Http Server 2.0.54

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
mbedthis-software
exploit available

Summary

Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.

Vulnerable Configurations

Part Description Count
Application
Mbedthis_Software
1

Exploit-Db

descriptionMbedthis AppWeb 2.2.2 URL Protocol Format String Vulnerability. CVE-2007-3009. Dos exploits for multiple platform
idEDB-ID:30187
last seen2016-02-03
modified2007-06-12
published2007-06-12
reporterNir Rachmel
sourcehttps://www.exploit-db.com/download/30187/
titleMbedthis AppWeb 2.2.2 URL Protocol Format String Vulnerability