CVE-2009-4490
Summary
| CVE | CVE-2009-4490 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-01-13 20:30:00 UTC |
| Updated | 2018-10-10 19:49:00 UTC |
| Description | mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730131 ACME Labs mini_httpd Log Escape Sequence Injection Vulnerability