LionMax Software WWW File Share Pro Remote Denial of Service Vulnerability
BID:9398
Info
LionMax Software WWW File Share Pro Remote Denial of Service Vulnerability
| Bugtraq ID: | 9398 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2004 12:00AM |
| Updated: | Jan 12 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to Dr_insane. |
| Vulnerable: |
LionMax Software WWW File Share Pro 2.46 LionMax Software WWW File Share Pro 2.42 LionMax Software WWW File Share Pro 2.41 LionMax Software WWW File Share Pro 2.40 LionMax Software WWW File Share Pro 2.6 0 |
| Not Vulnerable: |
LionMax Software WWW File Share Pro 2.48 |
Discussion
LionMax Software WWW File Share Pro Remote Denial of Service Vulnerability
It has been reported that WWW File Share Pro HTTP server may be prone to a remote denial of service condition. Successful exploitation of this vulnerability may allow a remote attacker to cause the vulnerable server to crash or hang, affectively denying service to legitimate users.
WWW File Share Pro versions 2.46 and prior may be prone to this issue.
Update: This vulnerability was originally fixed in WWW File Share Pro version 2.48, however, a new report suggests that version 2.60 is vulnerable to a similar attack. This has not been confirmed at the moment but version 2.60 is being added as a vulnerable version. This BID will be updated as more information becomes available.
It has been reported that WWW File Share Pro HTTP server may be prone to a remote denial of service condition. Successful exploitation of this vulnerability may allow a remote attacker to cause the vulnerable server to crash or hang, affectively denying service to legitimate users.
WWW File Share Pro versions 2.46 and prior may be prone to this issue.
Update: This vulnerability was originally fixed in WWW File Share Pro version 2.48, however, a new report suggests that version 2.60 is vulnerable to a similar attack. This has not been confirmed at the moment but version 2.60 is being added as a vulnerable version. This BID will be updated as more information becomes available.
Exploit / POC
LionMax Software WWW File Share Pro Remote Denial of Service Vulnerability
No exploit is required.
The following proof of concept has been provided:
http://www.example.com/AAA...[x3000]...AAA
http://www.example.com/AAA...[x5000]...AAA
No exploit is required.
The following proof of concept has been provided:
http://www.example.com/AAA...[x3000]...AAA
http://www.example.com/AAA...[x5000]...AAA