Denial of Service Vulnerability in Microsoft Site Server 3.0
CVE-2002-2081

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
31 December 2002

Summary

The vulnerability in Microsoft Site Server 3.0 arises from the cphost.dll component, which permits remote attackers to execute a denial of service attack. This is achieved by sending an HTTP POST request containing a file with an excessively long TargetURL parameter. As a result, the Site Server may terminate unexpectedly and leave the uploaded file in the c:\temp directory, leading to potential disk consumption issues that can disrupt the server's functionality.

References

EPSS Score

19% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.