CVE-2008-6520 Information
Feb 14, 2021
cve
Description
Multiple format string vulnerabilities in the SSI filter in Xitami Web Server 2.5c2 and possibly other versions allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a URI that ends in (1) .ssi (2) .shtm or (3) .shtml which triggers incorrect logging code involving the sendfmt function in the SMT kernel.
Reference
http://www.bratax.be/advisories/b013.html http://www.securityfocus.com/bid/28603 https://exchange.xforce.ibmcloud.com/vulnerabilities/41645
Share on: