PT-2001-1120 · Unknown · Small Http Server

Published

2001-01-09

·

Updated

2016-10-18

·

CVE-2000-0898

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Small HTTP Server version 2.01
Description The issue arises from the improper processing of Server Side Includes (SSI) tags that contain null values. This can be exploited by local users, and potentially remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
Recommendations For version 2.01, consider disabling the processing of SSI tags until a patch is available to prevent potential crashes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0898

Affected Products

Small Http Server