Allaire Spectra Data Indexing DoS...

- AV AC AU C I A
发布: 2000-01-04
修订: 2025-04-13

The web-based Configuration Wizard used to finalize settings during an install of Allaire Spectra is left on the machine after installation is complete, and can be used in a denial of service attack on the Spectra server. One of the functions performed by this wizard is indexing all data collections on the server. This process is CPU-intensive, and can be accessed remotely via a URL. An attacker could repeatedly start the indexing process, causing a degradation or denial of service.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息