Denial of Service in TinyWeb Web Server for Windows
A Denial of Service (DoS) vulnerability exists in Ritlabs TinyWeb 1.9.
Ken Pfeil
October 10, 2003
2 Min Read
Reported October 9, 2003 by Ziv Kamir.
VERSIONS AFFECTED
Ritlabs TinyWeb 1.9
DESCRIPTION
A Denial of Service (DoS) vulnerability exists in Ritlabs TinyWeb 1.9. By sending a specially formed HTTP GET request, an attacker can crash the server.
DEMONSTRATION
The discoverer posted the following demonstration as proof of concept:
A remote user can issue an HTTP GET request for /cgi-bin/.%00./dddd.html and cause the server to consume large amounts of CPU time (88%-92%)
VENDOR RESPONSE
Ritlabs has been notified.
CREDIT
Discovered byZiv Kamir.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like