← Back to CVE List

CVE-2019-7228

Published: 2019-06-27T15:15Z
Last Modified: 2024-11-21T04:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt