20010507 Advisory for Jana servermailing list
http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html CVE-2001-0558
T. Hauck Jana Server 1.45/1.46/2.0 - MS-DOS Device Name Denial of Service
Record summary
CVE-2001-0558 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBT. Hauck Jana Server 1.45/1.46/2.0 - MS-DOS Device Name Denial of ServiceExploitDB exploitby neme-dhcNot analyzed1 file
References
51817vdb entry
http://www.osvdb.org/1817 2704vdb entry
http://www.securityfocus.com/bid/2704 jana-server-device-dos(6521)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6521 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0558