Lucene search

K
cveMitreCVE-2007-2506
HistoryMay 04, 2007 - 1:19 a.m.

CVE-2007-2506

2007-05-0401:19:00
mitre
web.nvd.nist.gov
28
cve-2007-2506
webspeed
openedge 10.x
progress software
denial of service
remote attack

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.7

Confidence

High

EPSS

0.089

Percentile

94.6%

WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.

Affected configurations

Nvd
Node
progressprogressMatch9.1e
OR
progresswebspeedMatch3.0
OR
progresswebspeedMatch3.1a
OR
progresswebspeedMatch3.1d
OR
progresswebspeedMatch3.1e
VendorProductVersionCPE
progressprogress9.1ecpe:2.3:a:progress:progress:9.1e:*:*:*:*:*:*:*
progresswebspeed3.0cpe:2.3:a:progress:webspeed:3.0:*:*:*:*:*:*:*
progresswebspeed3.1acpe:2.3:a:progress:webspeed:3.1a:*:*:*:*:*:*:*
progresswebspeed3.1dcpe:2.3:a:progress:webspeed:3.1d:*:*:*:*:*:*:*
progresswebspeed3.1ecpe:2.3:a:progress:webspeed:3.1e:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.7

Confidence

High

EPSS

0.089

Percentile

94.6%

Related for CVE-2007-2506