Vulnerability Description
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Holger Zimmermann | Pi3Web | <= 2.0.3_pl1 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html
- http://secunia.com/advisories/32696Vendor Advisory
- http://www.osvdb.org/49998Exploit
- http://www.osvdb.org/49999
- http://www.securityfocus.com/archive/1/498575
- http://www.securityfocus.com/archive/1/498602
- http://www.securityfocus.com/archive/1/498770
- http://www.securityfocus.com/archive/1/498771
- http://www.securityfocus.com/archive/1/498865Exploit
- http://www.securityfocus.com/bid/32287ExploitPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46600
- https://www.exploit-db.com/exploits/7109
- http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html
- http://secunia.com/advisories/32696Vendor Advisory
- http://www.osvdb.org/49998Exploit
FAQ
What is CVE-2008-6938?
CVE-2008-6938 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obta...
How severe is CVE-2008-6938?
CVE-2008-6938 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-6938?
Check the references section above for vendor advisories and patch information. Affected products include: Holger Zimmermann Pi3Web.