PT-2001-1120 · Unknown · Small Http Server
Published
2001-01-09
·
Updated
2016-10-18
·
CVE-2000-0898
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Small HTTP Server version 2.01
Description
The issue arises from the improper processing of Server Side Includes (SSI) tags that contain null values. This can be exploited by local users, and potentially remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
Recommendations
For version 2.01, consider disabling the processing of SSI tags until a patch is available to prevent potential crashes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Small Http Server