Progress WebSpeed URL 拒绝服务漏洞

漏洞信息详情

Progress WebSpeed URL 拒绝服务漏洞

漏洞简介

Progress Software Progress 的OpenEdge 10.x中的WebSpeed 3.x允许远程攻击者借助一个信使URL,引起拒绝服务攻击(死循环和后台程序挂起)。该信使URL会调用不带有额外参数的_edit.r。

漏洞公告

参考网址

来源: BID

名称: 23778

链接:http://www.securityfocus.com/bid/23778

来源: BUGTRAQ

名称: 20070502 response Progress: Denial of Service attack against WebSpeed possible

链接:http://www.securityfocus.com/archive/1/archive/1/467376/100/0/threaded

来源: BUGTRAQ

名称: 20070501 Disable website access for sites running Webspeed

链接:http://www.securityfocus.com/archive/1/archive/1/467375/100/0/threaded

来源: MISC

链接:http://www.ishare.nl/

来源: SECUNIA

名称: 25129

链接:http://secunia.com/advisories/25129

来源: CONFIRM

名称: http://progress.atgnow.com/esprogress/resultDisplay.do?

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享