Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/10383 | mailing list vendor advisory |
http://www.securityfocus.com/bid/253 | vdb entry |