vendor:
WebWeaver
by:
d4rkgr3y
5.5
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: WebWeaver
Affected Version From: 01.06
Affected Version To: 01.06
Patch Exists: NO
Related CWE:
CPE: brs_webweaver:1.06
Platforms Tested:
Unknown
BRS WebWeaver Denial of Service
This exploit takes advantage of a vulnerability in BRS WebWeaver, allowing a remote attacker to crash or hang the software by sending a request with a large string value for the User-Agent parameter. The exploit sends a GET request with a specially crafted User-Agent header, causing the software to crash or hang.
Mitigation:
Upgrade to a version of BRS WebWeaver that is not affected by this vulnerability. Alternatively, filter and validate user input to prevent excessively long strings from being processed.