Vulnerability Description
GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Goahead | Goahead Webserver | <= 2.1.4 |
| Microsoft | Windows 95 | All versions |
| Microsoft | Windows 98 | All versions |
| Microsoft | Windows Me | All versions |
Related Weaknesses (CWE)
References
- http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-au
- http://data.goahead.com/Software/Webserver/2.1.8/release.htm#windows-95-98-me-au
FAQ
What is CVE-2003-1569?
CVE-2003-1569 is a vulnerability with a CVSS score of 5.0 (MEDIUM). GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ dev...
How severe is CVE-2003-1569?
CVE-2003-1569 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1569?
Check the references section above for vendor advisories and patch information. Affected products include: Goahead Goahead Webserver, Microsoft Windows 95, Microsoft Windows 98, Microsoft Windows Me.