CVE-2008-6938

Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:holger_zimmermann:pi3web:*:*:*:*:*:*:*:*
cpe:2.3:a:holger_zimmermann:pi3web:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:holger_zimmermann:pi3web:2.0:*:*:*:*:*:*:*
cpe:2.3:a:holger_zimmermann:pi3web:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:holger_zimmermann:pi3web:2.0.2_beta_1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:57

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html - () http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html -
References () http://secunia.com/advisories/32696 - Vendor Advisory () http://secunia.com/advisories/32696 - Vendor Advisory
References () http://www.osvdb.org/49998 - Exploit () http://www.osvdb.org/49998 - Exploit
References () http://www.osvdb.org/49999 - () http://www.osvdb.org/49999 -
References () http://www.securityfocus.com/archive/1/498575 - () http://www.securityfocus.com/archive/1/498575 -
References () http://www.securityfocus.com/archive/1/498602 - () http://www.securityfocus.com/archive/1/498602 -
References () http://www.securityfocus.com/archive/1/498770 - () http://www.securityfocus.com/archive/1/498770 -
References () http://www.securityfocus.com/archive/1/498771 - () http://www.securityfocus.com/archive/1/498771 -
References () http://www.securityfocus.com/archive/1/498865 - Exploit () http://www.securityfocus.com/archive/1/498865 - Exploit
References () http://www.securityfocus.com/bid/32287 - Exploit, Patch () http://www.securityfocus.com/bid/32287 - Exploit, Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/46600 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/46600 -
References () https://www.exploit-db.com/exploits/7109 - () https://www.exploit-db.com/exploits/7109 -

Information

Published : 2009-08-11 21:00

Updated : 2025-04-09 00:30


NVD link : CVE-2008-6938

Mitre link : CVE-2008-6938

CVE.ORG link : CVE-2008-6938


JSON object : View

Products Affected

holger_zimmermann

  • pi3web
CWE
CWE-20

Improper Input Validation