// For flags

CVE-2007-2506

Progress WebSpeed 3.0/3.1 - Denial of Service

Severity Score

7.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.

WebSpeed 3.x de OpenEdge 10.x en Progress Software Progress 9.1e, y otras versiones concretas 9.x, permite a atacantes remotos provocar una denegación de servicio (bucle infinito y congelación de demonio) mediante una URL de mensajero que invoca _edit.r sin parámetros adicionales, como demuestra realizando peticiones de cgiip.exe ó wsisa.dll con WService=wsbroker1/_edit.r en PATH_INFO.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-05-02 First Exploit
  • 2007-05-03 CVE Reserved
  • 2007-05-04 CVE Published
  • 2024-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress
Search vendor "Progress"
Progress
Search vendor "Progress" for product "Progress"
9.1e
Search vendor "Progress" for product "Progress" and version "9.1e"
-
Affected
Progress
Search vendor "Progress"
Webspeed
Search vendor "Progress" for product "Webspeed"
3.0
Search vendor "Progress" for product "Webspeed" and version "3.0"
-
Affected
Progress
Search vendor "Progress"
Webspeed
Search vendor "Progress" for product "Webspeed"
3.1a
Search vendor "Progress" for product "Webspeed" and version "3.1a"
-
Affected
Progress
Search vendor "Progress"
Webspeed
Search vendor "Progress" for product "Webspeed"
3.1d
Search vendor "Progress" for product "Webspeed" and version "3.1d"
-
Affected
Progress
Search vendor "Progress"
Webspeed
Search vendor "Progress" for product "Webspeed"
3.1e
Search vendor "Progress" for product "Webspeed" and version "3.1e"
-
Affected