← back
CVE-2009-4769

CVE-2009-4769

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 38%
from disclosure to weapon127 days
Published on NVDApr 20
1st PoC+127d
metasploitNov 17
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.