vendor:
TW-WebServer
by:
Shashank Pandey
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: TW-WebServer
Affected Version From: TW-WebServer/1, 3, 2, 0
Affected Version To: TW-WebServer/1, 3, 2, 0
Patch Exists: NO
Related CWE: N/A
CPE: //cpe:a:twilight_utilities:tw-webserver:1.3.2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
TW-WebServer/1, 3, 2, 0 Denial of Service Vulnerability
It has been reported that TW-WebServer is prone to a denial of service vulnerability. Reportedly when an excessive quantity of data is sent to the TW-Webserver as part of a malicious HTTP GET request the server will fail. Although unconfirmed, due to the nature of this vulnerability, an attacker may have the ability to supply and execute arbitrary code.
Mitigation:
Limit the amount of data that can be sent to the server as part of a malicious HTTP GET request.