Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.ioactive.com/pdfs/AccoriaWebServer.pdf | exploit |
http://www.kb.cert.org/vuls/id/245081 | third party advisory us government resource |