PT-2007-1623 · Fersch · Fersch Formbankserver

Publicado

2007-01-09

·

Atualizado

2017-07-29

·

CVE-2007-0138

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Fersch Formbankserver version 1.9
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash. This can be achieved by sending multiple requests with many /../ sequences in the Name parameter when the PATH INFO begins with either AbfrageForm or EingabeForm.
Recommendations For Fersch Formbankserver version 1.9, consider restricting access to the formbankcgi.exe to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the number of requests containing /../ sequences in the Name parameter to prevent daemon crashes.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0138

Produtos afetados

Fersch Formbankserver