
Topic: |
Easy Address Book Web Server Format String Vulnerability |
Credit: |
Revnic Vasile |
Date: |
2006.09.12 |
CWE: |
N/A |
CVE: |
CVE-2006-4654 (Show details)
Use CVE to see details like: - CVSS2, - Affected Software, - References |

| Risk |
Local |
| Remote |
| Low |
No |
| Yes |
Easy Address Book Web Server Format String Vulnerability
Software: Easy Address Book Web Server
Version: 1.2
Website: http://www.efssoft.com/
Description:
Easy Address Book Web Server is a Web Address Book software that allows users to view, search, add, edit, or administer
address books easily through a Web Browser.
Vulnerability:
By sending a specially crafted HTTP request, a remote attacker can crash or compromise the server.
Denial of Service example:
http://[host]/?%25n
Credit:
Discovered by Revnic Vasile
[ ASCII VERSION ]
|