| VID |
21094 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The '/cgi-bin/visadmin.exe' CGI is installed. OmniHTTPD is a web-server offered by Omnicron for the MS Windows platform. One of the CGI utilities it ships with and installs by default contains a bug that could, if exploited, lead to a denial of service condition on host it runs on. When the "visiadmin.exe" program is executed via CGI by issuing the request :
http://omni.server/cgi-bin/visadmin.exe?user=guest
It creates temporary files until the hard drive fills.
* References: http://www.iss.net/security_center/static/2271.php http://www.securityfocus.com/bid/1808 |
| Recommendation |
We are believed that this problem was fixed in the 2.0 Alpha 2 release of Omnicron OmniHTTPD. To be safe it is suggested that the visiadmin.exe program be removed from the cgi-bin directory. |
| Related URL |
CVE-1999-0970 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|