GeSHi 1.0.x - XML Parsing Remote Denial of Service



EKU-ID: 37500 CVE: CVE-2008-5185;OSVDB-50882 OSVDB-ID:
Author: Christian Hoffmann Published: 2008-11-20 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/32377/info

GeSHi is prone to a remote denial-of-service vulnerability.

Remote attackers can exploit this issue to cause the vulnerable application to enter an infinite loop, consuming excessive resources.

This issue affects versions prior to GeSHi 1.0.8.

The following example exploit is available:

<