Nombas ScriptEase:WebServer Edition GET Request Denial of Service Vulnerability
BID:4145
Info
Nombas ScriptEase:WebServer Edition GET Request Denial of Service Vulnerability
| Bugtraq ID: | 4145 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0298 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by 'ken'@FTU <[email protected]>. |
| Vulnerable: |
Nombas ScriptEase: Webserver Edition 0.95 win3.x Nombas ScriptEase: Webserver Edition 0.95 Solaris Nombas ScriptEase: Webserver Edition 0.95 ppc Nombas ScriptEase: Webserver Edition 0.95 OS/2 Nombas ScriptEase: Webserver Edition 0.95 Netware 5 Nombas ScriptEase: Webserver Edition 0.95 Linux Nombas ScriptEase: Webserver Edition 0.95 ISAPI win32 Nombas ScriptEase: Webserver Edition 0.95 IRIX Nombas ScriptEase: Webserver Edition 0.95 HP-UX Nombas ScriptEase: Webserver Edition 0.95 FreeBSD Nombas ScriptEase: Webserver Edition 0.95 CGIWINCGI win32 |
| Not Vulnerable: | |
Discussion
Nombas ScriptEase:WebServer Edition GET Request Denial of Service Vulnerability
Nombas ScriptEase:Webserver Edition is designed to allow the development of web based applications in Javascript. It includes the ability to execute Javascript code in response to CGI requests, and support for developer features such as remote debugging.
Reportedly versions of Nombas ScriptEase Webserver Edition are subject to a denial of service condition.
Submitting a GET request composed of arbitrary character sequences could result in varying error messages leading to a denial of service condition.
A restart of the server may be required in order to regain normal functionality.
Nombas ScriptEase:Webserver Edition is designed to allow the development of web based applications in Javascript. It includes the ability to execute Javascript code in response to CGI requests, and support for developer features such as remote debugging.
Reportedly versions of Nombas ScriptEase Webserver Edition are subject to a denial of service condition.
Submitting a GET request composed of arbitrary character sequences could result in varying error messages leading to a denial of service condition.
A restart of the server may be required in order to regain normal functionality.
Exploit / POC
Nombas ScriptEase:WebServer Edition GET Request Denial of Service Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Nombas ScriptEase:WebServer Edition GET Request Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.