httpdx 'USER' Command Remote Format String Vulnerability
BID:38135
Info
httpdx 'USER' Command Remote Format String Vulnerability
| Bugtraq ID: | 38135 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 07 2010 12:00AM |
| Updated: | Feb 09 2010 03:41PM |
| Credit: | loneferret |
| Vulnerable: |
httpdx httpdx 1.5.2 |
| Not Vulnerable: | |
Discussion
httpdx 'USER' Command Remote Format String Vulnerability
The 'httpdx' program is prone to a remote format-string vulnerability.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The issue affects httpdx 1.5.2; other versions may also be affected.
The 'httpdx' program is prone to a remote format-string vulnerability.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
The issue affects httpdx 1.5.2; other versions may also be affected.
Exploit / POC
httpdx 'USER' Command Remote Format String Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
httpdx 'USER' Command Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
httpdx 'USER' Command Remote Format String Vulnerability
References:
References:
- httpdx Project Page (SourceForge)