CVE-2008-6519
Xitami 2.2a-2.5c2 - Remote Code Execution via Format String in LRWP Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6519. PoCs published by bratax.
AI-analyzed exploit summary This exploit targets a format string vulnerability in Xitami Web Server v2.5c2. It sends a crafted payload with multiple '%s' format specifiers to trigger the bug, potentially causing a crash or arbitrary memory writes.
Description
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a Long Running Web Process (LRWP) request, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.
Exploits (1)
This exploit targets a format string vulnerability in Xitami Web Server v2.5c2. It sends a crafted payload with multiple '%s' format specifiers to trigger the bug, potentially causing a crash or arbitrary memory writes.