Xitami Webserver empty GET request DoS Vulnerability
BID:3511
Info
Xitami Webserver empty GET request DoS Vulnerability
| Bugtraq ID: | 3511 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2000 12:00AM |
| Updated: | Mar 29 2000 12:00AM |
| Credit: | Discovered by Roman <[email protected]> and submitted to SecurityFocus on March 29, 2000. |
| Vulnerable: |
Imatix Xitami for Windows 2.5 b4 Imatix Xitami for Windows 2.4 d7 Imatix Xitami for Windows 2.4 d2 |
| Not Vulnerable: |
Imatix Xitami for Windows 2.5 b5 Imatix Xitami for Windows 2.4 d9 |
Discussion
Xitami Webserver empty GET request DoS Vulnerability
Xitami is a webserver for Windows from Imatix.
Versions of Xitami are vulnerable to a denial of service attack.
It is possible to crash a server remotely by connecting with telnet on the web server port and submitting the following request:
GET<space><enter><enter>
Xitami is a webserver for Windows from Imatix.
Versions of Xitami are vulnerable to a denial of service attack.
It is possible to crash a server remotely by connecting with telnet on the web server port and submitting the following request:
GET<space><enter><enter>
Exploit / POC
Xitami Webserver empty GET request DoS Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.