Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-6938
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-6938

Description:
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/46600

SAID
  Secunia Advisory: SA32696

OSVDB
  49998
  49999

MILW0RM
  http://www.milw0rm.com/exploits/7109

BUGTRAQ
  http://www.securityfocus.com/archive/1/498575
  http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html
  http://www.securityfocus.com/archive/1/498602
  http://www.securityfocus.com/archive/1/498770
  http://www.securityfocus.com/archive/1/498771
  http://www.securityfocus.com/archive/1/498865

BID
  32287


Return to the previous page.