Vulnerability Description
OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the validation routines.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Owasp | Stinger | <= 2.4 |
References
- http://o0o.nu/~meder/o0o_bypassing_servlet_input_validation_filters.txt
- http://osvdb.org/39544
- http://secunia.com/advisories/26441PatchVendor Advisory
- http://securityreason.com/securityalert/3035
- http://www.securityfocus.com/archive/1/476288/100/0/threaded
- http://www.securityfocus.com/bid/25294ExploitPatch
- http://www.securitytracker.com/id?1018555
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35981
- http://o0o.nu/~meder/o0o_bypassing_servlet_input_validation_filters.txt
- http://osvdb.org/39544
- http://secunia.com/advisories/26441PatchVendor Advisory
- http://securityreason.com/securityalert/3035
- http://www.securityfocus.com/archive/1/476288/100/0/threaded
- http://www.securityfocus.com/bid/25294ExploitPatch
- http://www.securitytracker.com/id?1018555
FAQ
What is CVE-2007-4385?
CVE-2007-4385 is a vulnerability with a CVSS score of 6.8 (MEDIUM). OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulner...
How severe is CVE-2007-4385?
CVE-2007-4385 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4385?
Check the references section above for vendor advisories and patch information. Affected products include: Owasp Stinger.