MiniShare服务器远程服务拒绝漏洞

MiniShare服务器远程服务拒绝漏洞

漏洞ID 1107969 漏洞类型 其他
发布时间 2004-05-26 更新时间 2005-10-20
图片[1]-MiniShare服务器远程服务拒绝漏洞-安全小百科CVE编号 CVE-2004-2035
图片[2]-MiniShare服务器远程服务拒绝漏洞-安全小百科CNNVD-ID CNNVD-200405-060
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/24144
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200405-060
|漏洞详情
MiniShare1.3.2版本存在漏洞。远程攻击者借助畸形的HTTPGET或者没有适当数量的尾随CRLF序列的HEAD请求导致服务拒绝。
|漏洞EXP
source: http://www.securityfocus.com/bid/10417/info

Minishare is affected by a remote denial of service vulnerability. This issue is due to a failure of the application to handle improperly formed HTTP requests.

This issue will allow an attacker to cause the affected computer to stop responding, denying service to legitimate users.

GET:

1. GET /something HTTP/1.1
-
2. GET /something HTTP/1.1n
-


HEAD:

1. HEAD /something HTTP/1.1
-
2. HEAD /something HTTP/1.1n
-
|参考资料

来源:BID
名称:10417
链接:http://www.securityfocus.com/bid/10417
来源:OSVDB
名称:6432
链接:http://www.osvdb.org/6432
来源:sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?release_id=241158
来源:SECUNIA
名称:11715
链接:http://secunia.com/advisories/11715
来源:XF
名称:minishare-get-head-dos(16260)
链接:http://xforce.iss.net/xforce/xfdb/16260
来源:www.autistici.org
链接:http://www.autistici.org/fdonato/advisory/MiniShare1.3.2-adv.txt
来源:BUGTRAQ
名称:20040527DoSinMiniShare1.3.2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108563992129877&w;=2

相关推荐: 3D-FTP Client缓冲区溢出漏洞

3D-FTP Client缓冲区溢出漏洞 漏洞ID 1107291 漏洞类型 缓冲区溢出 发布时间 2003-04-28 更新时间 2003-12-31 CVE编号 CVE-2003-1472 CNNVD-ID CNNVD-200312-096 漏洞平台 Wi…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享