9.8
CVSSv3

CVE-2023-4491

Published: 04/10/2023 Updated: 06/10/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an malicious user to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.

Vulnerable Product Search on Vulmon Subscribe to Product

easy address book web server project easy address book web server 1.6

Exploits

Easy Address Book Web Server version 16 suffers from buffer overflow and cross site scripting vulnerabilities ...