PT-1998-1210 · Dwhttpd · Dwhttpd

Published

1998-08-23

·

Updated

2008-09-10

·

CVE-1999-1417

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dwhttpd version 3.1a4
Description The issue allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request. This is due to improper logging of the request.
Recommendations For dwhttpd version 3.1a4, consider disabling the logging of HTTP requests until a patch is available to prevent potential exploitation. Restrict access to the web server to minimize the risk of denial of service or arbitrary command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1417

Affected Products

Dwhttpd