Vulnerability record · CVE-2007-5067 · published 24 September 2007
CVE-2007-5067: Xitami Web Server buffer overflow via If-Modified-Since header
Imatix · Xitami
iMatix Xitami Web Server 2.5c2 contains multiple buffer overflows in xigui32.exe and xitami.exe triggered by a long If-Modified-Since header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code.
Description
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.exe.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated buffer overflow with public exploit code and very high EPSS, though the product is legacy and not in KEV.
What it is
iMatix Xitami Web Server 2.5c2 contains multiple buffer overflows in xigui32.exe and xitami.exe triggered by a long If-Modified-Since header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code.
Impact
Successful exploitation allows remote code execution in the context of the Xitami service, giving the attacker control of the affected host. Even without code execution, the overflow can crash the service, causing denial of service.
Attack surface
The flaw is reached over the network through HTTP requests to the web server, specifically via the If-Modified-Since header. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Public exploit code is referenced (SecurityFocus BID 25772 and Exploit-DB 4450), and EPSS is 0.73243 (99.4th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV.
What to do
- Upgrade or replace Xitami Web Server 2.5c2; the product is legacy and no vendor patch is indicated in the record.
- If upgrade is not possible, place the server behind a reverse proxy or WAF that rejects or normalizes oversized If-Modified-Since headers.
- Restrict network access to the Xitami service to trusted clients only.
- Monitor for crashes of xitami.exe or xigui32.exe and treat repeated crashes as potential exploitation attempts.
Detection
- Inspect HTTP request logs for abnormally long If-Modified-Since header values.
- Alert on process crashes or restarts of xitami.exe and xigui32.exe.
- Use network IDS signatures for buffer overflow attempts against Xitami HTTP headers.
- Correlate exploit-db 4450 or BID 25772 indicators with inbound HTTP traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5067 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5067), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.