Easy Address Book Web Server Remote Format String Vulnerability
BID:19842
CVE-2006-4654 |Info
Easy Address Book Web Server Remote Format String Vulnerability
| Bugtraq ID: | 19842 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2006 12:00AM |
| Updated: | Sep 06 2006 10:23PM |
| Credit: | Revnic Vasile is credited with the discovery of this vulnerability. |
| Vulnerable: |
EFS Software Easy Address Book Web Server 1.2 |
| Not Vulnerable: | |
Discussion
Easy Address Book Web Server Remote Format String Vulnerability
Easy Address Book Web Server is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied data before including it in the format-specifier argument to a formatted-printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected server process, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the service.
Easy Address Book Web Server version 1.2 is vulnerable to this issue; other versions may also be affected.
Easy Address Book Web Server is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied data before including it in the format-specifier argument to a formatted-printing function.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected server process, facilitating the complete compromise of affected computers. Failed exploit attempts will likely crash the service.
Easy Address Book Web Server version 1.2 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Easy Address Book Web Server Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept URI is sufficient to demonstrate this issue by crashing the vulnerable application:
http://www.example.com/?%25n
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
The following proof-of-concept URI is sufficient to demonstrate this issue by crashing the vulnerable application:
http://www.example.com/?%25n
Solution / Fix
Easy Address Book Web Server Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Easy Address Book Web Server Remote Format String Vulnerability
References:
References: