The HTTP service in quickweb.exe in Pablo Quick n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Quick_’n_easy_web_server | Pablosoftwaresolutions | * | 3.3.8 (including) |