GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
BID:33838
Info
GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 33838 |
| Class: | Unknown |
| CVE: |
CVE-2002-2427 CVE-2002-2428 CVE-2002-2429 CVE-2002-2430 CVE-2002-2431 CVE-2003-1568 CVE-2003-1569 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2002 12:00AM |
| Updated: | Feb 19 2009 10:10PM |
| Credit: | Richard Cullen, Luigi Auriemma, and the vendor. |
| Vulnerable: |
GoAhead Software GoAhead Webserver (Windows) 2.1 GoAhead Software GoAhead WebServer 2.1.5 GoAhead Software GoAhead WebServer 2.1.4 GoAhead Software GoAhead WebServer 2.1.3 GoAhead Software GoAhead WebServer 2.1.2 GoAhead Software GoAhead WebServer 2.1.1 GoAhead Software GoAhead WebServer 2.1 GoAhead Software GoAhead WebServer 2.0 |
| Not Vulnerable: |
GoAhead Software GoAhead WebServer 2.1.6 |
Discussion
GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
GoAhead WebServer is prone to an authentication-bypass vulnerability and multiple denial-of-service vulnerabilities.
A remote attacker may exploit these issues to gain access to protected documents or to create a denial-of-service condition.
Versions prior to GoAhead WebServer 2.1.6 are vulnerable.
GoAhead WebServer is prone to an authentication-bypass vulnerability and multiple denial-of-service vulnerabilities.
A remote attacker may exploit these issues to gain access to protected documents or to create a denial-of-service condition.
Versions prior to GoAhead WebServer 2.1.6 are vulnerable.
Exploit / POC
GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
An attacker can exploit these issues using readily available tools.
An attacker can exploit these issues using readily available tools.
Solution / Fix
GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
GoAhead WebServer Authentication Bypass and Multiple Denial of Service Vulnerabilities
References:
References:
- GoAhead WebServer 2.1.5 Release Notes (GoAhead Software)
- Vendor Homepage (GoAhead Software)