o0o.nu
http://o0o.nu/~meder/o0o_bypassing_servlet_input_validation_filters.txt CVE-2007-4385
OWASP Stinger - Filter Bypass
Record summary
CVE-2007-4385 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the validation routines.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOWASP Stinger - Filter BypassExploitDB exploitby Meder KydyralievNot analyzed1 file
References
939544vdb entry
http://osvdb.org/39544 26441Third-party advisory
http://secunia.com/advisories/26441 3035Third-party advisory
http://securityreason.com/securityalert/3035 20070813 [o0o] Bypassing servlet input validation filters (OWASP Stinger + Struts example)mailing list
http://www.securityfocus.com/archive/1/476288/100/0/threaded 25294vdb entry
http://www.securityfocus.com/bid/25294 1018555vdb entry
http://www.securitytracker.com/id?1018555 owasp-stinger-multipart-security-bypass(35981)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35981 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4385