Skip navigation

IMail IMonitor Subject to Denial of Service

 
IMail IMonitor Subject ot Denial of Service
Reported January 5, 2000 by
USSRLabs

VERSIONS AFFECTED
IMail IMonitor

DESCRIPTION

UssrLabs discovered a denial of service condition in IMail IMONITOR  Server for WinNT Version 5.08 and possibly other versions as well.

A cgi script entitle status.cgi checks to see if the server services are running. By executing the script numerous times in a short period of time Imonitor will crash citing an "Invalid Memory Address."

VENDOR RESPONSE

IPSwitch has been informed of the issue (tracking number IMS2000010500000096) however no fix was available at the time of this writing.

CREDITS
Discovered by
USSRLabs

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish