Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:MISC:VISNETIC-DOS

Severity

Minor

Recommended

No

Category

HTTP

Keywords

VisNetic WebSite Denial of Service

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: VisNetic WebSite Denial of Service


This signature detects attempts to exploit a known vulnerability in VisNetic WebSite. Versions 3.5.13.1 and earlier are vulnerable. Attackers can send a malicious OPTIONS request to crash the server.

Extended Description

VisNetic Website has been reported prone to a path disclosure vulnerability. It has been reported that a remote attacker may make a HTTP request for a CGI resource that does not exist and in doing so trigger an error. The resulting error message will disclose path information to the remote attacker. It should be noted that this vulnerability has been reported to affect VisNetic Website 3.5 Service release 17, prior versions are also likely affected.

Affected Products

  • Deerfield.com visnetic_website 3.5.13 .1
  • Deerfield.com visnetic_website 3.5.15
  • Deerfield.com visnetic_website 3.5.17

References

  • BugTraq: 8075
  • CVE: CVE-2003-0456
  • URL: http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=26322
  • URL: http://www.security.nnov.ru/search/document.asp?docid=3868
  • URL: http://www.deerfield.com/download/visnetic_website/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out