vendor:
Mongoose Web Server
by:
Ihsan Sencan
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Mongoose Web Server
Affected Version From: 6.9
Affected Version To: 6.9
Patch Exists: YES
Related CWE: N/A
CPE: a:cesanta:mongoose_web_server:6.9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
Mongoose Web Server 6.9 – Denial of Service (PoC)
This exploit is a proof of concept for a denial of service attack against Mongoose Web Server 6.9. The exploit creates multiple connections to the server and sends a 'BOOM' string to each connection, causing the server to crash.
Mitigation:
The vendor has released a patch to address this vulnerability.