4.3

CVE-2009-4775

Exploit

Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.

Data is provided by the National Vulnerability Database (NVD)
IpswitchWs Ftp Version12.0 Update- Editionhome
IpswitchWs Ftp Version12.0 Update- Editionpro
IpswitchWs Ftp Version12.0.1 Update- Editionhome
IpswitchWs Ftp Version12.0.1 Update- Editionpro
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 16.77% 0.947
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.