OSVDB ID: 17903

Title: Hosting Controller plansettings.asp Crafted Request DoS

Info

Disclosure

Jul 13, 2005

Discovery

Unknown

Dates

Exploit

Jul 13, 2005

Solution

Unknown

Description

Hosting Controller contains a flaw that may allow a remote denial of service. The issue is triggered when requesting the 'plansettings.asp' script with specific parameters, which causes the 'inetinfo.exe' process to consume all available CPU resources resulting in a loss of availability.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service
Impact: Loss of Availability
Exploit: Exploit Public
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Advanced Communications

Hosting Controller

6.1 hotfix 2.1

References

Credit

  • Soroush Dalili - irsdlyahoo.com - Grayhatz security group


Direct URL: http://osvdb.org/17903