CVE-2008-6938 describes a denial-of-service vulnerability in Pi3Web 2.0.3 before PL2, affecting installations on Windows as a desktop application. An attacker can crash or hang the server and disclose the full server pathname by requesting a non-executable file within the ISAPI directory, causing a DLL load failure. This vulnerability has a CVSS score of 4.3 (medium severity), indicating a network-based attack with medium complexity and partial availability impact. While not in CISA's KEV catalog, exploit modules exist in Metasploit and ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.3_pl1CPE matchmatch criteria | cpe:2.3:a:holger_zimmermann:pi3web:*:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:holger_zimmermann:pi3web:1.0.1:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:holger_zimmermann:pi3web:2.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:holger_zimmermann:pi3web:2.0.1:*:*:*:*:*:*:* | ||
2.0.2_beta_1CPE matchmatch criteria | cpe:2.3:a:holger_zimmermann:pi3web:2.0.2_beta_1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.