5
CVSSv2

CVE-2007-5036

Published: 24/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) via a crafted query string in an HTTPS request to (1) adLog.cgi, (2) post.cgi, or (3) ad.cgi, related to the "files filter."

Vulnerable Product Search on Vulmon Subscribe to Product

airdefense airsensor m520

Exploits

#!/usr/bin/perl -w # # Airsensor M520 HTTPD Remote Preauth Denial Of Service and Buffer Overflow PoC # # The vulnerability is caused due to an unspecified error in the cgis # files filter used for configure propierties This can be exploited by # sending a specially crafted HTTPS request (necessary authentication), # which wi ...

Github Repositories

Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)

CVE-2007-5036 Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC) Exploit-DB publication at wwwexploit-dbcom/exploits/4426/ Author Alex Hernandez aka (@_alt3kx_)