vendor:
MiniWeb Http Server
by:
gbr
7.5
CVSS
HIGH
Remote Denial of Service
CWE
Product Name: MiniWeb Http Server
Affected Version From: 2000.8.1
Affected Version To: 2000.8.19
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2
2007
MiniWeb Http Server 0.8.x Remote Denial of Service
The server doesn't do a sanity-check on 'Content-Length' value from POST Header, allowing the attacker to control the allocation size and the position in the 'pucPayload' char pointer to write. This could be used to trigger an exception.