Vulnerabilities > CVE-2004-2534 - Unspecified vulnerability in Fastream Netfile Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description | Fastream NETFile Web Server <= 7.1.2 (HEAD) DoS Exploit. CVE-2004-2534. Dos exploit for windows platform |
id | EDB-ID:1220 |
last seen | 2016-01-31 |
modified | 2005-09-16 |
published | 2005-09-16 |
reporter | karak0rsan |
source | https://www.exploit-db.com/download/1220/ |
title | Fastream NETFile Web Server <= 7.1.2 HEAD DoS Exploit |
Nessus
NASL family | Web Servers |
NASL id | FASTSTREAM_HEAD_DOS.NASL |
description | The remote host appears to be running FastStream NETFile Server version 7.1 or older. These versions do not close the connection when an HTTP HEAD request is received with the keep-alive option set. An attacker may exploit this flaw by sending multiple HEAD requests to the remote host, thus consuming all its file descriptors until it does not accept connections any more. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15764 |
published | 2004-11-19 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15764 |
title | Fastream NETFile FTP/Web Server HEAD Request Saturation DoS |
code |
|
References
- http://secunia.com/advisories/13268
- http://secunia.com/advisories/13268
- http://securitytracker.com/id?1012267
- http://securitytracker.com/id?1012267
- http://users.pandora.be/bratax/advisories/b003.html
- http://users.pandora.be/bratax/advisories/b003.html
- http://www.osvdb.org/12101
- http://www.osvdb.org/12101
- http://www.securityfocus.com/bid/11687
- http://www.securityfocus.com/bid/11687
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18192