21959Third-party advisory
http://secunia.com/advisories/21959 CVE-2006-4654
Easy Address Book Web Server 1.2 - Remote Format String
Record summary
CVE-2006-4654 has a selected CVSS score of 5.1; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBEasy Address Book Web Server 1.2 - Remote Format StringExploitDB exploitby Revnic VasileNot analyzed1 file
References
61529Third-party advisory
http://securityreason.com/securityalert/1529 20060904 Easy Address Book Web Server Format String Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/445262/100/0/threaded 19842vdb entry
http://www.securityfocus.com/bid/19842 easyaddressbook-url-format-string(28752)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/28752 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-4654