[] NeoSense

GeSHi 1.0.x - XML Parsing Remote Denial of Service

Author: Christian Hoffmann
type: dos
platform: multiple
port: 
date_added: 2008-11-20 
date_updated: 2014-03-30 
verified: 1 
codes: CVE-2008-5185;OSVDB-50882 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/32377/info

GeSHi is prone to a remote denial-of-service vulnerability.

Remote attackers can exploit this issue to cause the vulnerable application to enter an infinite loop, consuming excessive resources.

This issue affects versions prior to GeSHi 1.0.8.

The following example exploit is available:

<