Total vulnerabilities in the database
cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.
Software | From | Fixed in |
---|---|---|
microsoft / site_server | 3.0-sp2 | 3.0-sp2.x |
microsoft / site_server | 3.0-sp2_alpha | 3.0-sp2_alpha.x |
microsoft / site_server_commerce | 3.0-sp3_alpha | 3.0-sp3_alpha.x |
microsoft / site_server | 3.0-sp3_alpha | 3.0-sp3_alpha.x |
microsoft / site_server | 3.0-sp1_alpha | 3.0-sp1_alpha.x |
microsoft / site_server | 3.0 | 3.0.x |
microsoft / site_server_commerce | 3.0-sp1_alpha | 3.0-sp1_alpha.x |
microsoft / site_server | 3.0-apha | 3.0-apha.x |
microsoft / site_server | 3.0-sp4 | 3.0-sp4.x |
microsoft / site_server | 3.0-sp1 | 3.0-sp1.x |
microsoft / site_server | 3.0-sp4_alpha | 3.0-sp4_alpha.x |
microsoft / site_server_commerce | 3.0-sp4_alpha | 3.0-sp4_alpha.x |
microsoft / site_server_commerce | 3.0-alpha | 3.0-alpha.x |
microsoft / site_server | 3.0-sp3 | 3.0-sp3.x |
microsoft / site_server_commerce | 3.0-sp2_alpha | 3.0-sp2_alpha.x |
microsoft / site_server_commerce | 3.0 | 3.0.x |