GeSHi 1.0.x - XML Parsing Remote Denial of Service
Author: Christian Hoffmann
type: dos
platform: multiple
port:
date_added: 2008-11-20
date_updated: 2014-03-30
verified: 1
codes: CVE-2008-5185;OSVDB-50882
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/32377/info
GeSHi is prone to a remote denial-of-service vulnerability.
Remote attackers can exploit this issue to cause the vulnerable application to enter an infinite loop, consuming excessive resources.
This issue affects versions prior to GeSHi 1.0.8.
The following example exploit is available:
<