Allaire Spectra Data Indexing DoS Vulnerability
BID:916
Info
Allaire Spectra Data Indexing DoS Vulnerability
| Bugtraq ID: | 916 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 04 2000 12:00AM |
| Updated: | Jan 04 2000 12:00AM |
| Credit: | Publicized in Allaire bulletin ASB00-002 on January 4, 2000. |
| Vulnerable: |
Allaire Spectra 1.0 |
| Not Vulnerable: | |
Discussion
Allaire Spectra Data Indexing DoS Vulnerability
The web-based Configuration Wizard used to finalize settings during an install of Allaire Spectra is left on the machine after installation is complete, and can be used in a denial of service attack on the Spectra server. One of the functions performed by this wizard is indexing all data collections on the server. This process is CPU-intensive, and can be accessed remotely via a URL. An attacker could repeatedly start the indexing process, causing a degradation or denial of service.
The web-based Configuration Wizard used to finalize settings during an install of Allaire Spectra is left on the machine after installation is complete, and can be used in a denial of service attack on the Spectra server. One of the functions performed by this wizard is indexing all data collections on the server. This process is CPU-intensive, and can be accessed remotely via a URL. An attacker could repeatedly start the indexing process, causing a degradation or denial of service.