Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
References
Configurations
Information
Published : 2007-11-05 11:46
Updated : 2018-10-15 14:46
NVD link : CVE-2007-5825
Mitre link : CVE-2007-5825
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
firefly
- media_server