| VID |
12069 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The Abyss Web Server is vulnerable to a denial of service attack via the MS-DOS device name request. Abyss Web Server is a free personal Web server developed by Aprelium Technologies for Microsoft Windows, MacOS X, Linux, and FreeBSD. Abyss Web Server X1 for Microsoft Windows is vulnerable to a denial of service attack. By sending an HTTP request for a URL containing a MS-DOS device name (con, prn, aux, etc.) in the /cgi-bin directory, a remote attacker could cause the affected Web server to crash.
* References: http://www.osvdb.org/displayvuln.php?osvdb_id=11006 http://archives.neohapsis.com/archives/vulnwatch/2004-q4/0014.html
* Platforms Affected: Aprelium Technologies, Abyss Web Server X1 versions prior to 1.2.3.0 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of Abyss Web Server X1 (1.2.3.0 or later), available from the Abyss Web Server X1 Download Web page at http://www.aprelium.com/abyssws/download.php |
| Related URL |
(CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
17795 (ISS) |
|