Vulnonym.org

CVE-2008-2391 - Ophidian Confusions

Description

SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1.

Reference

http://www.codeplex.com/subsonic/WorkItem/View.aspx?WorkItemId=16112 http://www.portcullis-security.com/uplds/wildcard_attacks.pdf http://securityreason.com/securityalert/3898 https://exchange.xforce.ibmcloud.com/vulnerabilities/42562 http://www.securityfocus.com/archive/1/492233/100/0/threaded