Abyss Web Server MS-DOS Device Name DoS

high Nessus Plugin ID 15563

Synopsis

The remote web server is affected by a remote denial of service vulnerability.

Description

It was possible to kill the web server by sending an MS-DOS device name in an HTTP request.

Solution

Upgrade to version 1.2.3.0 or higher.

See Also

https://seclists.org/vulnwatch/2004/q4/13

Plugin Details

Severity: High

ID: 15563

File Name: abyss_msdos_dos.nasl

Version: 1.19

Type: remote

Family: Web Servers

Published: 10/25/2004

Updated: 6/12/2020

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

Vulnerability Publication Date: 10/20/2004

Reference Information

Secunia: 12900