7.5
CVE-2008-0097
- EPSS 2.46%
- Veröffentlicht 08.01.2008 02:46:00
- Zuletzt bearbeitet 16.06.2026 22:48:56
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Georgia Softworks ≫ Ssh2 Server Version <= 7.01.0003
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.46% | 0.824 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://aluigi.altervista.org/adv/gswsshit-adv.txt
http://secunia.com/advisories/28307
http://securityreason.com/securityalert/3517
http://www.securityfocus.com/archive/1/485725/100/0/threaded