Description
|
|
Two vulnerabilities have been identified in BlueDragon Server, which could be exploited by remote attackers to cause a denial of service or execute arbitrary scripting code.
The first flaw is due to an error when handling HTTP requests containing an MS-DOS device name and the ".cfm" or "cfml" file extension, which could be exploited by remote attackers to cause a vulnerable server to stop responding.
The second vulnerability is due to an error when handling a malformed URL and displaying the default error page, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|