Mbedthis AppWeb URL Protocol Format String Vulnerability
BID:24454
Info
Mbedthis AppWeb URL Protocol Format String Vulnerability
| Bugtraq ID: | 24454 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3009 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2007 12:00AM |
| Updated: | Jun 13 2007 06:49PM |
| Credit: | Nir Rachmel is credited with discovering this issue. |
| Vulnerable: |
Embedthis Software Appweb 2.2.2 |
| Not Vulnerable: | |
Discussion
Mbedthis AppWeb URL Protocol Format String Vulnerability
Mbedthis AppWeb is prone to a format-string vulnerability because the application fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
This issue affects only applications that were built with logging enabled and installed with no "ErrorLog" directive in 'appweb.conf'.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
AppWeb 2.2.2 is reported vulnerable; other versions may also be affected.
Mbedthis AppWeb is prone to a format-string vulnerability because the application fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
This issue affects only applications that were built with logging enabled and installed with no "ErrorLog" directive in 'appweb.conf'.
Successful exploits may allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
AppWeb 2.2.2 is reported vulnerable; other versions may also be affected.
Exploit / POC
Mbedthis AppWeb URL Protocol Format String Vulnerability
An attacker may exploit this issue through a browser.
The following example request is available:
'GET %n://localhost:80/" request'
An attacker may exploit this issue through a browser.
The following example request is available:
'GET %n://localhost:80/" request'
Solution / Fix
Mbedthis AppWeb URL Protocol Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Mbedthis AppWeb URL Protocol Format String Vulnerability
References:
References:
- Support for the AppWeb HTTP Server (appwebserver forum)
- Mbedthis AppWeb Homepage (Mbedthis AppWeb)