Vulnerabilities > CVE-2018-16789 - Infinite Loop vulnerability in Shellinabox Project Shellinabox

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
shellinabox-project
CWE-835

Summary

libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149978/shellinabox220-dos.txt
idPACKETSTORM:149978
last seen2018-10-27
published2018-10-27
reporterImre Rad
sourcehttps://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.html
titleShell In A Box 2.2.0 Denial Of Service