First published: Tue Dec 31 2002(Updated: )
cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Site Server Commerce | =3.0 | |
Microsoft Site Server Commerce | =3.0-apha | |
Microsoft Site Server Commerce | =3.0-sp1 | |
Microsoft Site Server Commerce | =3.0-sp1_alpha | |
Microsoft Site Server Commerce | =3.0-sp2 | |
Microsoft Site Server Commerce | =3.0-sp2_alpha | |
Microsoft Site Server Commerce | =3.0-sp3 | |
Microsoft Site Server Commerce | =3.0-sp3_alpha | |
Microsoft Site Server Commerce | =3.0-sp4 | |
Microsoft Site Server Commerce | =3.0-sp4_alpha | |
Microsoft Commerce Server | =3.0 | |
Microsoft Commerce Server | =3.0-alpha | |
Microsoft Commerce Server | =3.0-sp1_alpha | |
Microsoft Commerce Server | =3.0-sp2_alpha | |
Microsoft Commerce Server | =3.0-sp3_alpha | |
Microsoft Commerce Server | =3.0-sp4_alpha |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2081 is classified as a denial-of-service vulnerability that can cause disk consumption on the affected server.
To fix CVE-2002-2081, it is recommended to upgrade to a non-vulnerable version of Microsoft Site Server.
CVE-2002-2081 affects various versions of Microsoft Site Server 3.0, including SP1, SP2, SP3, and SP4.
CVE-2002-2081 allows remote attackers to execute an HTTP POST attack that can lead to a denial of service.
The vulnerability in CVE-2002-2081 leaves the uploaded files in the c:\temp directory of the server.