Vulnerabilities > CVE-2001-0493 - Unspecified vulnerability in MAX Feoktistov Small Http Server 2.03

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
max-feoktistov
nessus

Summary

Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.

Vulnerable Configurations

Part Description Count
Application
Max_Feoktistov
1

Nessus

NASL familyWeb Servers
NASL idHTTP_W98_DEVNAME_DOS.NASL
descriptionIt was possible to freeze or reboot Windows by reading a MS/DOS device through HTTP, using a file name like CON\CON, AUX.htm, or AUX. An attacker could exploit this flaw to deny service to the affected system.
last seen2020-06-01
modified2020-06-02
plugin id10930
published2002-03-29
reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10930
titleMultiple Web Server on Windows MS/DOS Device Request Remote DOS