Korean
<< Back
VID 22389
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description A version of FirstClass which is older or as old as than version 8.0 is detected as installed on the host. OpenText FirstClass is a collaborative groupware application. FirstClass version 8.0 and earlier versions are vulnerable to a denial of service attack. The vulnerability is caused due to an error in the handling of large requests. By sending a large amount of POST requests to "/Search" over multiple connections, a remote attacker could cause a vulnerable server to stop responding

* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.

* References:
http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0321.html
http://www.securitytracker.com/alerts/2004/Dec/1012478.html

* Platforms Affected:
OpenText, FirstClass version 8.0 and earlier versions
Apple Computer, Inc., Mac OS 10.x
Microsoft Windows Any version
Recommendation No upgrade or patch available as of December 2005.

Upgrade to a version of FirstClass greater than 8.0.0, when new fixed version becomes available from the OpenText FirstClass Downloads Web site at http://www.firstclass.com/Downloads/
Related URL CVE-2004-2496 (CVE)
Related URL 11877 (SecurityFocus)
Related URL 18424 (ISS)