10
CVSSv2

CVE-2008-6519

Published: 25/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in Xitami Web Server 2.2a up to and including 2.5c2, and possibly other versions, allows remote malicious users to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a Long Running Web Process (LRWP) request, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.

Vulnerable Product Search on Vulmon Subscribe to Product

imatix xitami 2.4d7

imatix xitami 2.5c2

imatix xitami 2.5

imatix xitami 2.2a

imatix xitami 2.4

Exploits

/** * * PoC exploit for Xitami Web Server v25c2 LRWP processing format string bug * Advisory is available at: wwwbrataxbe/advisories/b013html * (multiple vulnerabilities! check it out!) * * @author: bratax * @url: wwwbrataxbe/ * @email: bratax@gmailcom * * Thanks to BuzzDee for learning me how to use reverse code engi ...