Short Name |
HTTP:MISC:VISNETIC-DOS |
---|---|
Severity |
Minor |
Recommended |
No |
Category |
HTTP |
Keywords |
VisNetic WebSite Denial of Service |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability in VisNetic WebSite. Versions 3.5.13.1 and earlier are vulnerable. Attackers can send a malicious OPTIONS request to crash the server.
VisNetic Website has been reported prone to a path disclosure vulnerability. It has been reported that a remote attacker may make a HTTP request for a CGI resource that does not exist and in doing so trigger an error. The resulting error message will disclose path information to the remote attacker. It should be noted that this vulnerability has been reported to affect VisNetic Website 3.5 Service release 17, prior versions are also likely affected.