BRS WebWeaver httpd `User-Agent` Remote Denial of Service Vulnerability
BID:8947
Info
BRS WebWeaver httpd `User-Agent` Remote Denial of Service Vulnerability
| Bugtraq ID: | 8947 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2003 12:00AM |
| Updated: | Nov 01 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to d4rkgr3y <[email protected]>. |
| Vulnerable: |
BRS WebWeaver 1.0 6 BRS WebWeaver 1.0 5 BRS WebWeaver 1.0 4 BRS WebWeaver 1.0 3 BRS WebWeaver 1.0 2 BRS WebWeaver 1.0 1 BRS WebWeaver 0.63 beta BRS WebWeaver 0.62 beta BRS WebWeaver 0.61 beta BRS WebWeaver 0.60 beta BRS WebWeaver 0.52 beta BRS WebWeaver 0.51 beta BRS WebWeaver 0.50 beta BRS WebWeaver 0.49 beta BRS WebWeaver 62 beta |
| Not Vulnerable: | |
Discussion
BRS WebWeaver httpd `User-Agent` Remote Denial of Service Vulnerability
It has been reported that BRS WebWeaver may be prone to a denial of service issue that may allow a remote attacker to cause the software to crash or hang. The issue presents itself when the server receives a request containing a large string value for the `User-Agent` parameter.
Successful exploitation of this issue may allow an attacker to cause the software to crash or hang.
BRS WebWeaver versions 1.06 and prior have been reported to be prone to this issue.
It has been reported that BRS WebWeaver may be prone to a denial of service issue that may allow a remote attacker to cause the software to crash or hang. The issue presents itself when the server receives a request containing a large string value for the `User-Agent` parameter.
Successful exploitation of this issue may allow an attacker to cause the software to crash or hang.
BRS WebWeaver versions 1.06 and prior have been reported to be prone to this issue.
Exploit / POC
BRS WebWeaver httpd `User-Agent` Remote Denial of Service Vulnerability
Exploit code has been provided:
Exploit code has been provided: