Vulnerabilities > CVE-2009-2300 - Resource Management Errors vulnerability in Phion Airlock web Application Firewall 4.110.41

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause a denial of service (resource consumption) via a crafted request.

Vulnerable Configurations

Part Description Count
Application
Phion
1

Common Weakness Enumeration (CWE)