Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
John Roy Pi3Web超长请求远程缓冲区溢出漏洞
Vulnerability Description
John Roy Pi3Web是一个免费的、多线程的、高度可定制、可扩展的HTTP服务器,它也提供了对CGI和ISAPI的支持。Pi3Web有Windows、Linux、Solaris下的版本可供使用。 Pi3Web for Windows v2.0 beta1和beta2在处理超长的CGI请求时存在一个缓冲区溢出漏洞,可能使Pi3Web服务器拒绝服务。 当向Pi3Web服务器发送几次带超长(超过260字符长并以一串'.'结束)的CGI文件请求时,服务器程序会因为缓冲区溢出而崩溃。服务器必须重新启动以恢复
CVSS Information
N/A
Vulnerability Type
N/A