Reptile Web Server Reptile Web Server 20020105 - Denial of Service



EKU-ID: 29025 CVE: CVE-2004-2120;OSVDB-34293 OSVDB-ID:
Author: Donato Ferrante Published: 2004-01-23 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/9482/info

Reptile has been reported prone to a remote denial of service vulnerability. It has been reported that this issue exists because the affected server does not time out on incomplete requests. A remote attacker may exploit this vulnerability to deny service to legitimate users.

To test the vulnerability simply send to the webserver some (about 10)
strings like:

GET index.htm

without specify the HTTP* at the end of the GET request, and where
the requested file must be avaible in the public_html directory.