CVE-2008-1401 Information

Description

Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to execute arbitrary code via format string specifiers in the URI which is recorded in a log file.

Reference

http://aluigi.altervista.org/adv/netinsp-adv.txt http://secunia.com/advisories/29421 http://www.securityfocus.com/archive/1/489704/100/0/threaded http://www.securityfocus.com/bid/28266 https://www.exploit-db.com/exploits/5269

Share on: