Vulnerabilities > Mbedthis Software

DATE CVE VULNERABILITY TITLE RISK
2007-06-04 CVE-2007-3009 Unspecified vulnerability in Mbedthis Software Mbedthis Appweb Http Server 2.0.54
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
4.3
2007-06-04 CVE-2007-3008 Information Exposure vulnerability in Mbedthis Software Mbedthis Appweb Http Server
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
4.3
2004-12-31 CVE-2004-2317 Multiple vulnerability in Mbedthis Software AppWeb HTTP Server
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
network
low complexity
mbedthis-software
5.0
2004-12-31 CVE-2004-2316 Denial Of Service vulnerability in Mbedthis Software AppWeb HTTP Server Empty Options Request
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request containing an MS-DOS device name such as COM1.
network
low complexity
mbedthis-software
5.0
2004-12-31 CVE-2004-2315 Denial Of Service vulnerability in Mbedthis Software AppWeb HTTP Server Empty Options Request
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.
network
low complexity
mbedthis-software
5.0
2004-12-31 CVE-2004-2213 Multiple vulnerability in Mbedthis Software AppWeb HTTP Server
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
network
low complexity
mbedthis-software
5.0