Easy Address Book Web Server Query Remote Format String

This script is Copyright (C) 2006-2011 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by a format string vulnerability.

Description :

It appears that the remote web server is affected by a remote format
string issue. Using a specially crafted URL containing a format
string specifier, an unauthenticated, remote attacker can crash the
affected application and possibly execute arbitrary code on the remote
host.

See also :

http://www.securityfocus.com/archive/1/445262/30/0/threaded

Solution :

Unknown at this time.

Risk factor :

Medium / CVSS Base Score : 5.1
(CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 4.6
(CVSS2#E:POC/RL:U/RC:ND)
Public Exploit Available : true

Family: CGI abuses

Nessus Plugin ID: 22305 (eabws_arg_format_string.nasl)

Bugtraq ID: 19842

CVE ID: CVE-2006-4654