First published: Mon Sep 17 2007(Updated: )
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BTCPayServer | =0.93.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4915 is considered a high severity vulnerability due to the potential for remote code execution via crafted input.
To fix CVE-2007-4915, update the Boa web server to a version later than 0.93.15 that addresses this vulnerability.
CVE-2007-4915 affects devices using the Boa web server version 0.93.15, including FreeLan RO80211G-AP.
CVE-2007-4915 allows remote attackers to change the admin password by using a long username in an HTTP Basic Authentication request.
Yes, CVE-2007-4915 can be exploited without authentication since it allows attackers to manipulate memory directly.