PY Software Active Webcam WebServer ‘Filelist.html’拒绝服务攻击漏洞

PY Software Active Webcam WebServer ‘Filelist.html’拒绝服务攻击漏洞

漏洞ID 1108516 漏洞类型 未知
发布时间 2005-03-10 更新时间 2005-03-10
图片[1]-PY Software Active Webcam WebServer ‘Filelist.html’拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2005-0731
图片[2]-PY Software Active Webcam WebServer ‘Filelist.html’拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200503-089
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25207
https://www.securityfocus.com/bid/90181
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200503-089
|漏洞详情
PYSoftwareActiveWebcamWebServer(webcam.exe)5.5允许远程攻击者通过对Filelist.html的直接请求实施拒绝服务攻击(CPU消耗)。
|漏洞EXP
source: http://www.securityfocus.com/bid/12778/info

Active Webcam webserver is reported prone to multiple vulnerabilities. The following individual issues are reported:

The first issue, a denial of service is reported to manifest when a request is received for a file that exists on a floppy drive.

A remote attacker may exploit this issue to deny service for legitimate users.

A denial of service is reported to exist when the 'Filelist.html' file is requested.

A remote attacker may exploit this issue to deny service for legitimate users.

An installation path disclosure vulnerability is reported to affect Active Webcam. It is reported that a request for a non-existent file will result in an error message that contains the installation path of the software.

A remote attacker may exploit this issue to gain information regarding the filesystem on a target computer.

An information disclosure vulnerability is reported to affect Active Webcam. It is reported that this vulnerability exists because different error messages are returned to a request for a file depending on whether the file exists or not.

A remote attacker may exploit this issue to gain information regarding the filesystem on a target computer. 

http://www.example.com:8080/Filelist.html
http://www.example.com:8080/A:a.txt
http://www.example.com:8080/a
|受影响的产品
PY Software Active WebCam 5.5
|参考资料

来源:XF
名称:active-webcam-filelist-dos(19650)
链接:http://xforce.iss.net/xforce/xfdb/19650
来源:MISC
链接:http://secway.org/advisory/ad20050104.txt
来源:SECUNIA
名称:14553
链接:http://secunia.com/advisories/14553
来源:FULLDISC
名称:20050310MultipleVulnerabilitiesofPYSoftwareActiveWebcamWebServer
链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-03/0216.html

相关推荐: AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability

AppleShare IP FTP Server RMD Command Denial Of Service Vulnerability 漏洞ID 1099151 漏洞类型 Failure to Handle Exceptional Conditions 发布…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享