7.8
CVSSv2

CVE-2007-5984

Published: 15/11/2007 Updated: 15/10/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

classes/Url.php in Justin Hagstrom AutoIndex PHP Script prior to 2.2.4 allows remote malicious users to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation."

Vulnerable Product Search on Vulmon Subscribe to Product

justin hagstrom autoindex php script 2.0.4

justin hagstrom autoindex php script 2.0.5

justin hagstrom autoindex php script 2.2.1

justin hagstrom autoindex php script 2.2.2

justin hagstrom autoindex php script 2.0.0

justin hagstrom autoindex php script 2.0.1

justin hagstrom autoindex php script 2.1.0

justin hagstrom autoindex php script 2.1.1

justin hagstrom autoindex php script 2.0.6

justin hagstrom autoindex php script 2.0.7

justin hagstrom autoindex php script 2.2.3

justin hagstrom autoindex php script 2.0.2

justin hagstrom autoindex php script 2.0.3

justin hagstrom autoindex php script 2.1.2

justin hagstrom autoindex php script 2.2.0

Exploits

source: wwwsecurityfocuscom/bid/26410/info AutoIndex PHP Script is prone to a remote denial-of-service vulnerability because the application fails to properly handle unexpected input Successfully exploiting this issue allows remote attackers to consume excessive CPU resources, potentially denying service to legitimate users AutoIndex ...