vendor:
by:
Lance M. Havok
5.5
CVSS
MEDIUM
HTTP Server Redirect
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Proof of Concept for MOAB-25-01-2007
This script demonstrates a proof of concept for the MOAB-25-01-2007 vulnerability. It starts an HTTP server on the specified port (default 80) and waits for incoming connections. When a connection is made, it generates a random content length and extracts the user agent from the request. It then responds with a 301 redirect to a non-existent URL and sends a response body filled with 'X' characters of the random content length. This vulnerability can be used for HTTP server redirection attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update the affected HTTP server software to the latest version, as this vulnerability was reported and addressed in 2007.