|
|
| |
| Oxide Webserver 2.0.4 is prone to a denial of service vulnerability |
| |
Credit:
The information has been provided by Antu Sanadi.
|
| |
Vulnerable Systems:
* Oxide Webserver 2.0.4
Oxide Webserver v2.0.4 is prone to a remote Denial of Service vulnerability as it fails to handle crafted requests from the client properly.
The vulnerability is caused by an error in handling some crafted characters in HTTP GET requests, which causes the server to crash.
Successful exploitation could allow an attacker to crash a vulnerable server.
References:
-----------
http://secpod.org/blog/?p=516
http://sourceforge.net/projects/oxide
http://sourceforge.net/projects/oxide-ws/files
http://secpod.org/advisories/SecPod_Oxide_WebServer_DoS_Vuln.txt
Proof of Concept:
----------------
http://www.example.com:80/?.
http://www.example.com:80/<.
http://www.example.com:80/$.
http://www.example.com:80/cc.
Solution:
----------
Not available
Risk Factor:
-------------
CVSS Score Report:
ACCESS_VECTOR = NETWORK
ACCESS_COMPLEXITY = LOW
AUTHENTICATION = NONE
CONFIDENTIALITY_IMPACT = NONE
INTEGRITY_IMPACT = NONE
AVAILABILITY_IMPACT = COMPLETE
EXPLOITABILITY = PROOF_OF_CONCEPT
REMEDIATION_LEVEL = UNAVAILABLE
REPORT_CONFIDENCE = CONFIRMED
CVSS Base Score = 7.8 (High) (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Disclosure Timeline:
Published: 2012-07-20
|
|
blog comments powered by
|