The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Intraweb_component | Atozed_software | * | 8.0 (including) |
Intraweb_component | Atozed_software | 9.0 (including) | 9.0 (including) |