Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
References
Configurations
History
No history.
Information
Published : 2007-11-05 19:46
Updated : 2025-04-09 00:30
NVD link : CVE-2007-5825
Mitre link : CVE-2007-5825
CVE.ORG link : CVE-2007-5825
JSON object : View
Products Affected
firefly
- media_server
CWE
CWE-134
Use of Externally-Controlled Format String