Bug: Easy Address Book Web Server Format String Vulnerability (WLB-2006090057 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: Easy Address Book Web Server Format String Vulnerability
 Credit: Revnic Vasile
 Date: 2006.09.12
 CWE: N/A
 CVE: CVE-2006-4654 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
Low
No
Yes

Easy Address Book Web Server Format String Vulnerability

Software: Easy Address Book Web Server

Version: 1.2

Website: http://www.efssoft.com/

Description:

Easy Address Book Web Server is a Web Address Book software that allows users to view, search, add, edit, or administer
address books easily through a Web Browser.

Vulnerability:

By sending a specially crafted HTTP request, a remote attacker can crash or compromise the server.

Denial of Service example:

http://[host]/?%25n

Credit:

Discovered by Revnic Vasile

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com