CVE-2007-3009
MEDIUM 4.3EPSS 2.2%
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P - EPSS
- 2.23% chance of exploitation in the next 30 days, 82th percentile
- Published
- 2007-06-04
- Updated
- 2024-08-07