PT-2007-1623 · Fersch · Fersch Formbankserver

Published

2007-01-09

·

Updated

2017-07-29

·

CVE-2007-0138

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Fersch Formbankserver version 1.9
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash. This can be achieved by sending multiple requests with many /../ sequences in the Name parameter when the PATH INFO begins with either AbfrageForm or EingabeForm.
Recommendations For Fersch Formbankserver version 1.9, consider restricting access to the formbankcgi.exe to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the number of requests containing /../ sequences in the Name parameter to prevent daemon crashes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0138

Affected Products

Fersch Formbankserver