CVE-2007-2506
Last modified
CVE-2007-2506 is a vulnerability of currently unknown severity. WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.. EPSS estimates a 3.97% chance of exploitation in the next 30 days.
Description
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Progress | Progress | 9.1e |
| Progress | Webspeed | 3.0 |
| Progress | Webspeed | 3.1a |
| Progress | Webspeed | 3.1d |
| Progress | Webspeed | 3.1e |
References
- http://secunia.com/advisories/25129Vendor Advisory
- http://www.securityfocus.com/bid/23778Exploit, Patch
- http://secunia.com/advisories/25129Vendor Advisory
- http://www.securityfocus.com/bid/23778Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2506?
How severe is CVE-2007-2506?
How do I fix CVE-2007-2506?
Are you affected by CVE-2007-2506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
