header-logo
Suggest Exploit
vendor:
602Pro Lan Suite
by:
SecurityFocus
8.3
CVSS
HIGH
Denial of Service
400
CWE
Product Name: 602Pro Lan Suite
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

Denial of Service Vulnerability in 602Pro Lan Suite

A denial of service vulnerability exists in versions of 602Pro Lan Suite. A remote attacker may connect to port 80 of the vulnerable host. Via this connection, the attacker submits a long request composed of at least 1033 characters. This excess input causes an overflows of the server's input buffer and crashes Lansuite.exe and all applicable services.

Mitigation:

Ensure that the server is running the latest version of 602Pro Lan Suite and that all security patches are applied.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/2543/info

A denial of service vulnerability exists in versions of 602Pro Lan Suite.

A remote attacker may connect to port 80 of the vulnerable host. Via this connection, the attacker submits a long request composed of at least 1033 characters. This excess input causes an overflows of the server's input buffer and crashes Lansuite.exe and all applicable services. 

GET / HTTP/1.1
Proxy-Authorization:AAAAAAAAAAAAA.....

Where A x 1033 or more characters, as long as its
over 1032, it will work.