Lotus Domino bad URL database Denial of Service Vulnerability
BID:3656
Info
Lotus Domino bad URL database Denial of Service Vulnerability
| Bugtraq ID: | 3656 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2001 12:00AM |
| Updated: | Dec 08 2001 12:00AM |
| Credit: | Posted to BugTraq on December 7th 2001 by Sebastien EXT-MICHAUD <[email protected]> |
| Vulnerable: |
Lotus Domino 5.0.8 -french Lotus Domino 5.0.5 -french |
| Not Vulnerable: | |
Discussion
Lotus Domino bad URL database Denial of Service Vulnerability
Lotus Domino 5.0.5 and 5.0.8 (French) are vulnerable to denial of services initiated by sending a specific malformed URL to the web server. By prefacing a database name with "/./" in a URL, access to that database can be disabled - eg, "http://server/./webadmin.nsf". This could be used for denial of service attacks on Lotus Domino servers. The French versions were reported vulnerable, but other versions may suffer from this issue as well (untested).
Lotus Domino 5.0.5 and 5.0.8 (French) are vulnerable to denial of services initiated by sending a specific malformed URL to the web server. By prefacing a database name with "/./" in a URL, access to that database can be disabled - eg, "http://server/./webadmin.nsf". This could be used for denial of service attacks on Lotus Domino servers. The French versions were reported vulnerable, but other versions may suffer from this issue as well (untested).
Exploit / POC
Lotus Domino bad URL database Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lotus Domino bad URL database Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Lotus Domino bad URL database Denial of Service Vulnerability
References:
References: