CVE Database
/

CVE-2007-5825

Back to search

CVE-2007-5825

Published: Nov 5, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-1597
vendor-advisory
x_refsource_DEBIAN
26310
vdb-entry
x_refsource_BID
28269
third-party-advisory
x_refsource_SECUNIA
30661
third-party-advisory
x_refsource_SECUNIA
GLSA-200712-18
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now