CVE-2009-4769
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 38%
from disclosure to weapon127 days
Published on NVDApr 20
1st PoC+127d
metasploitNov 17
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16732unverifiedexploitdbwww.exploit-db.com/exploits/16794unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/60181http://osvdb.org/60182http://www.metasploit.com/redmine/projects/framework/repository/revisions/7569/entry/modules/exploits/windows/ftp/httpdx_tolog_format.rbhttp://www.metasploit.com/redmine/projects/framework/repository/revisions/7569/entry/modules/exploits/windows/http/httpdx_tolog_format.rbhttp://www.vupen.com/english/advisories/2009/3312