5
CVSSv2

CVE-2007-3159

Published: 11/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

http.c in MiniWeb Http Server 0.8.x allows remote malicious users to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header.

Vulnerable Product Search on Vulmon Subscribe to Product

miniweb http server miniweb http server 0.8.1

miniweb http server miniweb http server 0.8.19

Exploits

# MiniWeb Http Server 08x Remote Denial of Service # MiniWeb site sourceforgenet/projects/miniweb/ # Author: gbr # # Tested running the server under Windows XP SP2 # # Description: # # The server doesn't do a sanity-check on 'Content-Length' value from POST Header, allowing the attacker to control # the allocation size and the position in ...