PT-2003-2241 · Efs · Easy File Sharing Web Server
Published
2003-12-31
·
Updated
2017-07-20
·
CVE-2003-1296
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Easy File Sharing (EFS) Web Server version 1.2
Description
The issue allows remote authenticated users to cause a denial of service. This can be achieved by either entering an "empty symbol" in the
Title field or by providing certain data in the Your Message field, possibly a long argument.Recommendations
For Easy File Sharing (EFS) Web Server version 1.2, consider restricting access to the
Title and Your Message fields until a fix is available. As a temporary workaround, validate and sanitize user input in these fields to prevent denial of service attacks.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easy File Sharing Web Server