The HTTP service in quickweb.exe in Pablo Quick n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Quick_’n_easy_web_server | Pablosoftwaresolutions | * | 3.3.8 (including) |