Advertisement






IMENDIO PLANNER REMOTE FILENAME FORMAT STRING VULNERABILITY

CVE Category Price Severity
CVE-2004-0845 CWE-134 $Unknown High
Author Risk Exploitation Type Date
d9p3 High Remote 2006-08-15
CPE PURL
cpe:cpe:None/imendio-planner-remote-filename-format-string-vulnerability pkg:pkg:None/imendio-planner-remote-filename-format-string-vulnerability
CVSS EPSS EPSSP
CVSS:4.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006080070

Below is a copy:

By : LoneEagle

E-mail : king_purba (at) yahoo.co (dot) uk [email concealed]

http://kandangjamur.net

Affected :

IMENDIO PLANNER 0.13

PROJECT MANAGEMENT FEDORA 4.

Impact : System Acces

From : Remote

Severity : Moderately Critical

Description:

------------

Imendio planner was failed when opening file name format string.

Remote attacker can exploit this vulnerabilty by creating a malicious

filename that contain format string specifier. Successfull attacking can be used

for executing arbitrary code.

Solution :

----------

Don't open file from untursted source.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum