CNCVE编号:CNCVE-20020030 CVE编号: 安全级别:高 漏洞中文描述: Nombas ScriptEase:Webserver Edition是一个用来使开发者以Javascript进行基于Web应用开发的工具。它有应CGI程序的要求执行Javascript的能力,它还为开发者提供了远程调试的功能。ScriptEase:Webserver Edition实现上存在漏洞,远程攻击者可能利用漏洞对服务器进程实施拒绝服务攻击。通过提交一些包含特殊字符的GET请求给服务器,会导致产生许多的错误消息,在收到“Press any key…”的返回信息后,服务器会停止响应正常的服务请求,从而形成拒绝服务,需要重启才能恢复功能。 漏洞英文描述: Nombas ScriptEase:Webserver Edition is designed to allow the development of web based applications in Javascript. It includes the ability to execute Javascript code in response to CGI requests, and support for developer features such as remote debugging. Reportedly versions of Nombas ScriptEase Webserver Edition are subject to a denial of service condition. Submitting a GET request composed of arbitrary character sequences could result in varying error messages leading to a denial of service condition. A restart of the server may be required in order to regain normal functionality 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0216.html http://www.nombas.com/us/sewse/index.htm 系统类型:其他 漏洞类型:输入有效性检查错误