CVE-2014-0050

Apache Commons FileUpload <1.3.1 - DoS

Title source: llm

Description

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

Exploits (5)

exploitdb WORKING POC VERIFIED
by Trustwave's SpiderLabs · rubydosmultiple
https://www.exploit-db.com/exploits/31615
nomisec WORKING POC 1 stars
by jrrdev · poc
https://github.com/jrrdev/cve-2014-0050
nomisec WRITEUP
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2014-0050-commons-fileupload-vulnerable
nomisec WRITEUP
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2014-0050-commons-fileupload-vulnerable
metasploit WORKING POC
by Unknown, ribeirux · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/http/apache_commons_fileupload_dos.rb

References (69)

... and 49 more

Scores

EPSS 0.9271
EPSS Percentile 99.8%

Details

CWE
CWE-264
Status published
Products (47)
apache/commons_fileupload 1.0
apache/commons_fileupload 1.1
apache/commons_fileupload 1.1.1
apache/commons_fileupload 1.2
apache/commons_fileupload 1.2.1
apache/commons_fileupload 1.2.2
apache/commons_fileupload < 1.3
apache/tomcat 7.0.0 (2 CPE variants)
apache/tomcat 7.0.1
apache/tomcat 7.0.2 (2 CPE variants)
... and 37 more
Published Apr 01, 2014
Tracked Since Feb 18, 2026