The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/45408 - | |
References | () http://www.web-app.org/cgi-bin/index.cgi?action=forum&board=how_to&op=display&num=9458 - | |
References | () http://www.web-app.org/downloads/WebAPPv0.9.9.7.zip - Patch |
Information
Published : 2007-06-26 23:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3422
Mitre link : CVE-2007-3422
CVE.ORG link : CVE-2007-3422
JSON object : View
Products Affected
web-app.org
- webapp
CWE