Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-6938
Description:Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.
Test IDs: 1.3.6.1.4.1.25623.1.0.900402  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-6938
BugTraq ID: 32287
http://www.securityfocus.com/bid/32287
Bugtraq: 20081122 Re: Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498575
Bugtraq: 20081122 Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2008-11/0171.html
Bugtraq: 20081124 Re: Re: Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498602
Bugtraq: 20081130 Re: Re: Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498770
Bugtraq: 20081201 Re: Re: Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498771
Bugtraq: 20081203 Re: Re: Re: Wrong report: BID 32287, Pi3Web ISAPI DoS vulnerability (Google Search)
http://www.securityfocus.com/archive/1/498865
https://www.exploit-db.com/exploits/7109
http://www.osvdb.org/49998
http://www.osvdb.org/49999
http://secunia.com/advisories/32696
XForce ISS Database: pi3web-isapi-dos(46600)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46600




© 1998-2025 E-Soft Inc. All rights reserved.