| VID |
21146 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The '/scripts/visadmin.exe' CGI is installed. OmniHTTPD is a web-server offered by Omnicron for the MS Windows platform. One of the CGI utilities it ships with and installs by default contains a bug that could, if exploited, lead to a denial of service condition on host it runs on. When the "visiadmin.exe" program is executed via CGI by issuing the request :
http://omni.server/scripts/visadmin.exe?user=guest
It creates temporary files until the hard drive fills |
| Recommendation |
We are believed that this problem was fixed in the 2.0 Alpha 2 release of Omnicron OmniHTTPD. To be safe it is suggested that the visiadmin.exe program be removed from the scripts directory. |
| Related URL |
CVE-1999-0970 (CVE) |
| Related URL |
1808 (SecurityFocus) |
| Related URL |
2271 (ISS) |
|