Vulnerabilities > CVE-2007-3009 - Unspecified vulnerability in Mbedthis Software Mbedthis Appweb Http Server 2.0.54

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
mbedthis-software
exploit available

Summary

Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.

Vulnerable Configurations

Part Description Count
Application
Mbedthis_Software
1

Exploit-Db

descriptionMbedthis AppWeb 2.2.2 URL Protocol Format String Vulnerability. CVE-2007-3009. Dos exploits for multiple platform
idEDB-ID:30187
last seen2016-02-03
modified2007-06-12
published2007-06-12
reporterNir Rachmel
sourcehttps://www.exploit-db.com/download/30187/
titleMbedthis AppWeb 2.2.2 URL Protocol Format String Vulnerability