CVE-2007-5984 Information

Description

classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a 00 sequence in the dir parameter to index.php which triggers an erroneous \recursive calculation.\

Reference

http://autoindex.sourceforge.net/change_log.html http://osvdb.org/45282 http://securityreason.com/securityalert/3360 http://www.securityfocus.com/archive/1/483592/100/0/threaded http://www.securityfocus.com/bid/26410 https://exchange.xforce.ibmcloud.com/vulnerabilities/38437

Share on: