ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via the coment parameter to (1) show_video.php or (2) topic.php.
References
Configurations
History
21 Nov 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2012-11/0039.html - Exploit | |
References | () http://packetstormsecurity.org/files/117975/AWCM-2.2-Access-Bypass.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/79927 - |
Information
Published : 2012-11-26 12:45
Updated : 2024-11-21 01:39
NVD link : CVE-2012-2438
Mitre link : CVE-2012-2438
CVE.ORG link : CVE-2012-2438
JSON object : View
Products Affected
awcm-cms
- ar_web_content_manager
CWE
CWE-399
Resource Management Errors