5
CVSSv2

CVE-2006-1275

Published: 19/03/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

GGZ Gaming Zone 0.0.12 allows remote malicious users to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) trailing ' (apostrophe) character on the ID attribute in a PLAYER XML tag, (2) joining with a long ID attribute or non-trailing ' characters, which causes a <none> name to be assigned, and then disconnecting, or (3) a long CDATA message attribute, which prevents closing tags from being added to the string.

Vulnerable Product Search on Vulmon Subscribe to Product

ggz gaming zone ggz gaming zone 0.0.12

Exploits

source: wwwsecurityfocuscom/bid/17094/info GGZ Gaming Zone is prone to multiple remote denial-of-service vulnerabilities These issues are due to improper input sanitization An attacker may cause the victim's connection to the server to terminate, causing a denial of service to legitimate users Examples have been provided: &lt;PLAYER ...