[Forgot Password]
Login  Register Subscribe

23631

 
 

117687

 
 

98218

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2008-6938

Date: (C)2009-08-11   (M)2017-10-04 


Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

CVSS Score: 4.3Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL





Reference:
http://www.securityfocus.com/archive/1/498575
http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html
http://www.securityfocus.com/archive/1/498602
http://www.securityfocus.com/archive/1/498770
http://www.securityfocus.com/archive/1/498771
http://www.securityfocus.com/archive/1/498865
BID-32287
SECUNIA-32696
OSVDB-49998
OSVDB-49999
EXPLOIT-DB-7109
pi3web-isapi-dos(46600)

CWE    1
CWE-20

© 2013 SecPod Technologies