|
Brought to you by:
Suppliers of:
|
|
|
| |
| WebBBS Pro is "the World's Most Advanced Web package providing an easy to use and secure Web Server". Multiple remotely exploitable vulnerabilities allow attackers to cause the product to crash. |
| |
Credit:
The information has been provided by Ziv Kamir (the * vulnerability), and by SecurITeam Experts (the CON and AUX vulnerabilities).
|
| |
Vulnerable systems:
* WebBBS Pro version 1.8
By sending several forms of Windows related DoS attacks, it is possible to cause the remote server to do any of the following: crash, consume large amounts of memory, and consume large amounts of CPU time.
Exploit:
Using the following URL, it is possible to cause the server to consume large amounts of CPU time:
http://host/*
http://host/CON
Using the following URL, it is possible to cause the server to hang:
http://host/AUX
Vendor status:
The product appears to no longer exist/abandoned, currently the company provides another product called Raven.
|
|
|
|
|