Vulnerabilities
Vulnerable Software
Jasper:  >> Httpdx  Security Vulnerabilities
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.
CVSS Score
9.3
EPSS Score
0.621
Published
2010-04-20
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to obtain privileged access.
CVSS Score
7.5
EPSS Score
0.005
Published
2010-04-20
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.
CVSS Score
5.0
EPSS Score
0.071
Published
2009-12-31
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
CVSS Score
10.0
EPSS Score
0.789
Published
2009-10-16
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header.
CVSS Score
10.0
EPSS Score
0.193
Published
2009-10-11


Contact Us

Shodan ® - All rights reserved