RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
BID:24974
Info
RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
| Bugtraq ID: | 24974 |
| Class: | Design Error |
| CVE: |
CVE-2007-3816 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2007 12:00AM |
| Updated: | Sep 27 2007 01:09AM |
| Credit: | SecNiche Security disclosed this vulnerability. |
| Vulnerable: |
Anders Møller JWIG 1.1-1 |
| Not Vulnerable: | |
Discussion
RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
Anders Møller JWIG is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions and to execute loop control statements in the browser context of a victim user.
Anders Møller JWIG 1.1-1 is vulnerable; prior versions may also be affected.
NOTE: This BID is being retired because further investigation shows that JWIG is not vulnerable to this issue.
Anders Møller JWIG is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause denial-of-service conditions and to execute loop control statements in the browser context of a victim user.
Anders Møller JWIG 1.1-1 is vulnerable; prior versions may also be affected.
NOTE: This BID is being retired because further investigation shows that JWIG is not vulnerable to this issue.
Exploit / POC
RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
NOTE: An independent source is refuting this issue. This BID has been updated to reflect this claim.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
NOTE: An independent source is refuting this issue. This BID has been updated to reflect this claim.
References
RETIRED: Anders Møller JWIG Template Remote Denial Of Service Vulnerability
References:
References:
- JWIG Web Site (Anders Møller)
- [CVE-2007-3816][Advisory] JWIG Context-Dependent Template Calling Dos (Aditya K Sood
)