← Back

CVE-2009-4769

nvd nist
Published: Apr 20, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.

Affected (5)

Products: Jasper: Httpdx
1 product
Httpdx
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Jasper
Version 1.4.5
Version 1.4.6
Version 1.4.6b
Version 1.4
Version 1.5

Timeline

No history available yet.