Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6520

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-6520
Last Modified 25 Mar 2009 12:00:00
Published 25 Mar 2009 02:30:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-6520

Summary

Multiple format string vulnerabilities in the SSI filter in Xitami Web Server 2.5c2, and possibly other versions, allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a URI that ends in (1) .ssi, (2) .shtm, or (3) .shtml, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.

Vulnerable Systems

Application

  • Imatix Xitami 2.5c2


References

XF - xitami-ssi-logging-code-execution(41645)

BID - 28603

MISC - http://www.bratax.be/advisories/b013.html


Last Updated: 27 May 2016 10:49:13