vendor:
Simple HTTPD
by:
shinnai
5.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: Simple HTTPD
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Simple HTTPD 1.3 /aux Denial of Service
This exploit targets the Simple HTTPD 1.3 server by sending a specific GET request to the /aux endpoint, causing a denial of service condition. The vulnerability exists in the way the server handles this particular request, leading to a crash or unresponsiveness. The exploit utilizes a socket connection to send the malicious request to the target host and port. This vulnerability was discovered by shinnai and the details can be found on their website at http://shinnai.altervista.org.
Mitigation:
There is no known mitigation or remediation for this vulnerability. It is recommended to upgrade to a newer version of the Simple HTTPD server or switch to a different web server software.