Denial of Service Condition in Savant Web Server 3.0

A vulnerability exists in Michael Lamont’s Savant Web Server 3.0. By accessing the server and appending the URL with a series of percent characters (i.e., %), a malicious attacker can crash the server.

Ken Pfeil

March 7, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported March 8, 2001, by XatrixSecurity.

VERSION AFFECTED

  • Savant Web Server 3.0 for Windows 95/98, Millennium Edition (Me), NT, 2000

DESCRIPTION

Avulnerability exists in Michael Lamont’s Savant Web Server 3.0. By accessingthe server and appending the URL with a series of percent characters (i.e., %),a malicious attacker can crash the server.

 

DEMONSTRATION

 

For example, http://www.somevulnerableserver.com/%%%will crash the server.

 

VENDOR RESPONSE

 

Thevendor has been notified, but hasnot issued a fix. The SourceForgeWeb site is tracking this vulnerability.

 

CREDIT

Discovered by Xatrix Security.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like