← All CVEs

CVE-2008-6938

medium · 4.3

Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

4.3
CVSS
26.5%
EPSS (exploit prob.)
98th
EPSS percentile
2009-08-11
Published

AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
holger_zimmermannpi3web<= 2.0.3_pl1
holger_zimmermannpi3web1.0.1
holger_zimmermannpi3web2.0
holger_zimmermannpi3web2.0.1
holger_zimmermannpi3web2.0.2_beta_1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-6938