CVE Vulnerabilities

CVE-2007-2506

Published: May 04, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.

Affected Software

Name Vendor Start Version End Version
Progress Progress 9.1e (including) 9.1e (including)
Webspeed Progress 3.0 (including) 3.0 (including)
Webspeed Progress 3.1a (including) 3.1a (including)
Webspeed Progress 3.1d (including) 3.1d (including)
Webspeed Progress 3.1e (including) 3.1e (including)

References