|
|
| |
| Plug and Play server is a HTTP / FTP / NEWS / MAIL / TELNET / DNS / DHCP / HTTP-PROXY server, running on top of the Windows platforms. The product has been found to contain a vulnerability that allows remote attackers to cause the HTTP Proxy to no longer respond to legitimate requests by sending it a malformed HTTP request. |
| |
Credit:
The information has been provided by Oliver Karow.
|
| |
Vulnerable systems:
* Plug and Play Web Server version 1.0002c
Sending the following request "GET /asdf.? HTTP/1.0" to TCP Port 8080 will stop the Proxy Service, showing a "Runtime Error 12001 - Parameter 1 of the method used is invalid or not appropriate" on the console.
|
|
|
|
|