SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Server/CGI)  >   Sambar Server Vendors:   Sambar Technologies
Sambar Web Server Sample CGI Allows Remote Users to Crash the Web Server
SecurityTracker Alert ID:  1003246
SecurityTracker URL:  http://securitytracker.com/id/1003246
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Jan 16 2002
Impact:   Denial of service via network
Exploit Included:  Yes  
Version(s): 5.1; possibly other versions
Description:   SecurityOffice.net reported a denial of service vulnerability in the Sambar Server. A remote user can cause a sample CGI script provided with the web server to crash the web service.

A remote user can reportedly send a long HTTP GET request several times to cause the web service to crash:

GET /cgi-win/cgitest.exe?AAAAA...(Ax4000)...AAAAA HTTP/1.1

Impact:   A remote user can cause the web service to crash.
Solution:   No solution was available at the time of this entry.
Vendor URL:  www.sambar.com/ (Links to External Site)
Cause:   Exception handling error
Underlying OS:   Windows (Any)

Message History:   None.


 Source Message Contents

Date:  Wed, 16 Jan 2002 01:57:17 +0200
Subject:  Sambar Webserver v5.1 DoS Vulnerability


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sambar Webserver v5.1 DoS Vulnerability

Type:
DoS, crashes Daemon

Release Date:
December 16, 2002

Product / Vendor:
Sambar Server is a multi-threaded HTTP server for Microsoft Windows
and Unix systems. 

http://www.sambar.com

Summary:
Sambar Webserver is bundled with a sample cgi script (testcgi.exe)
which create security flaw. Server crashes after sending very long
request a few times.

GET /cgi-win/cgitest.exe?AAAAA...(Ax4000)...AAAAA HTTP/1.1

Tested:
Windows 2000 / Sambar Webserver 5.1

Vulnerable:
Sambar Webserver 5.1 (And may be other)

Disclaimer:
http://www.securityoffice.net is not responsible for the misuse or
illegal use of any of the information and/or the software listed on
this security advisory.

Author:
Tamer Sahin
ts@securityoffice.net
http://www.securityoffice.net

Tamer Sahin
http://www.securityoffice.net
PGP Key ID: 0x2B5EDCB0 Fingerprint:
B96A 5DFC E0D9 D615 8D28 7A1B BB8B A453 2B5E DCB0

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQA/AwUBPETB3LuLpFMrXtywEQJxoACgg8Qkb4oNBO0Mk0eUNsrZMqmNM6kAoORT
xqjMjk6Fv2K+UzKuoDtcx7Dz
=owpC
-----END PGP SIGNATURE-----




 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC