|
 |
|
Mbedthis AppWeb HTTP Request Denial of Service Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA10710
|
|
|
Release Date:
|
2004-01-26
|
|
Last Update:
|
2004-02-03
|
|
|
Critical:
|

Moderately critical
|
|
Impact:
|
DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Mbedthis AppWeb 1.x
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Ziv Kamir has reported two vulnerabilities in Mbedthis AppWeb, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerabilities are caused due to errors when handling various HTTP requests. This can be exploited to crash the process by sending an empty OPTIONS request or a GET request containing a DOS device name.
Example:
http://[victim]/COM1
The vulnerabilities affect version 1.0.0 for Windows NT/2K.
Solution: Update to version 1.0.1.
http://www.mbedthis.com/downloads/appWeb/index.html
Provided and/or discovered by: Ziv Kamir
Changelog: 2004-02-03: Vendor releases fix. Updated information about affected versions.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
1 Related Secunia Security Advisories
|
|
|
1. Mbedthis AppWeb Multiple Vulnerabilities
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|