CVE-2006-1364 Information
Description
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components or are restricted documents located under the ASP.NET application path.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://hackingspirits.com/vuln-rnd/w3wp-remote-dos.zip http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044291.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044292.html http://securitytracker.com/id?1015825 http://www.securiteam.com/windowsntfocus/5KP0O0KI0Y.html http://www.securityfocus.com/archive/1/428622/100/0/threaded http://www.securityfocus.com/bid/17188 https://exchange.xforce.ibmcloud.com/vulnerabilities/25392 https://www.exploit-db.com/exploits/1601
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: