PT-1998-1210 · Dwhttpd · Dwhttpd
Published
1998-08-23
·
Updated
2008-09-10
·
CVE-1999-1417
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
dwhttpd version 3.1a4
Description
The issue allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request. This is due to improper logging of the request.
Recommendations
For dwhttpd version 3.1a4, consider disabling the logging of HTTP requests until a patch is available to prevent potential exploitation. Restrict access to the web server to minimize the risk of denial of service or arbitrary command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dwhttpd