TinyServer Multiple漏洞

TinyServer Multiple漏洞

漏洞ID 1107655 漏洞类型 未知
发布时间 2004-01-24 更新时间 2005-10-20
图片[1]-TinyServer Multiple漏洞-安全小百科CVE编号 CVE-2004-2117
图片[2]-TinyServer Multiple漏洞-安全小百科CNNVD-ID CNNVD-200401-060
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23595
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200401-060
|漏洞详情
TinyServer1.1版本存在漏洞。远程攻击者借助例如(1)无需HTTP版本(HTTP/1.1)的GET请求,或(2)无GET的请求或HTTP版本的畸形HTTP请求导致服务拒绝(崩溃)。
|漏洞EXP
source: http://www.securityfocus.com/bid/9485/info
 
TinyServer is prone to multiple vulnerabilities.
 
A directory traversal issue is present in TinyServer that could allow a remote user to view or download any file to which the server has access.
 
A denial of service issue exists due to the failure of the server to check input strings received. Attackers can crash the server by simply sending malformed HTTP GET requests. Sending an HTTP GET request with excessively long data can also cause the server to fail. It is not known if this issue may also result in code execution.
 
A cross-site scripting issue is also present in the server. This could allow for theft of cookie-based authentication credentials or other attacks. 

GET /index.htm

index.htm

GET /aaaaaa[ 260 of a ]aaa HTTP/1.1
|参考资料

来源:XF
名称:tinyserver-string-dos(14928)
链接:http://xforce.iss.net/xforce/xfdb/14928
来源:BID
名称:9485
链接:http://www.securityfocus.com/bid/9485
来源:www.autistici.org
链接:http://www.autistici.org/fdonato/advisory/tinyServer1.1%5B1.0.5%5D-adv.txt
来源:BUGTRAQ
名称:20040124TinyServer1.1(1.0.5)MultipleVulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107496530806730&w;=2
来源:OSVDB
名称:3709
链接:http://www.osvdb.org/3709
来源:SECUNIA
名称:10707
链接:http://secunia.com/advisories/10707

相关推荐: JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities

JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities 漏洞ID 1097599 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 200…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享