20010308 def-2001-10: Websweeper Infinite HTTP Request DoSmailing list
http://www.securityfocus.com/archive/1/167406 CVE-2001-0460
Baltimore Technologies WEBsweeper 4.0 - Denial of Service
Record summary
CVE-2001-0460 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBaltimore Technologies WEBsweeper 4.0 - Denial of ServiceExploitDB exploitby honoriakNot analyzed1 file
References
3websweeper-http-dos(6214)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6214 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0460