- Description
- Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:N/A:P
- nvd@nist.gov
- CWE-20
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:holger_zimmermann:pi3web:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F55CD4D4-080A-4877-82D5-5AFE2A2BC3BE",
"versionEndIncluding": "2.0.3_pl1"
},
{
"criteria": "cpe:2.3:a:holger_zimmermann:pi3web:1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC69C856-3621-467B-87D6-5F376C65E65E"
},
{
"criteria": "cpe:2.3:a:holger_zimmermann:pi3web:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13A3A7A6-0BE6-4D07-ABD0-8BB5965A66E7"
},
{
"criteria": "cpe:2.3:a:holger_zimmermann:pi3web:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5D6ABEC-7F14-473A-A6BD-F0A444AE8843"
},
{
"criteria": "cpe:2.3:a:holger_zimmermann:pi3web:2.0.2_beta_1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E3F46E6-D47D-475E-9E69-D06A93BE25C3"
}
],
"operator": "OR"
}
]
}
]