The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/48111 | exploit vdb entry third party advisory |