7.8
CVSSv2

CVE-2006-1159

Published: 12/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote malicious users to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

efs software efs web server 3.2

Exploits

source: wwwsecurityfocuscom/bid/17046/info Easy File Sharing Web Server is prone to multiple input-validation vulnerabilities The application fails to properly sanitize user-supplied input before using it in dynamically generated content The issues include HTML-injection, denial-of-service, and arbitrary file-upload vulnerabilities ...