Korean
<< Back
VID 21146
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The '/scripts/visadmin.exe' CGI is installed.
OmniHTTPD is a web-server offered by Omnicron for the MS Windows platform. One of the CGI utilities it ships with and installs by default contains a bug that could, if exploited, lead to a denial of service condition on host it runs on. When the "visiadmin.exe" program is executed via CGI by issuing the request :

http://omni.server/scripts/visadmin.exe?user=guest

It creates temporary files until the hard drive fills
Recommendation We are believed that this problem was fixed in the 2.0 Alpha 2 release of Omnicron OmniHTTPD. To be safe it is suggested that the visiadmin.exe program be removed from the scripts directory.
Related URL CVE-1999-0970 (CVE)
Related URL 1808 (SecurityFocus)
Related URL 2271 (ISS)