Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3422
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3422

Description:
The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.

CVE Status:
Candidate

References:

OSVDB
  45408

CONFIRM
  http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip
  http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458


Return to the previous page.