PT-2006-7507 · Fersch · Fersch Formbankserver
Bl0Od3R
·
Published
2006-12-31
·
Updated
2017-10-19
·
CVE-2006-6910
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Fersch Formbankserver version 1.9
Description:
The issue allows remote attackers to cause a denial of service, resulting in a daemon crash. This is achieved by sending multiple requests with many /../ sequences in the
Name parameter when the PATH INFO begins with 'Abfrage'.Recommendations:
For Fersch Formbankserver version 1.9, consider restricting access to the
formbankcgi.exe to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the Name parameter in requests when the PATH INFO starts with 'Abfrage' to prevent daemon crashes.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fersch Formbankserver