Sambar Server Search Script Mixed Query Vulnerability
BID:7975
Info
Sambar Server Search Script Mixed Query Vulnerability
| Bugtraq ID: | 7975 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2003 12:00AM |
| Updated: | Jun 19 2003 12:00AM |
| Credit: | Discovery credited to Lorenzo Manuel Hernandez Garcia-Hierro. |
| Vulnerable: |
Sambar Server 5.1 Sambar Server 5.0 beta6 Sambar Server 5.0 beta5 Sambar Server 5.0 beta4 Sambar Server 5.0 beta3 Sambar Server 5.0 beta2 Sambar Server 5.0 beta1 Sambar Server 4.4 Beta 3 Sambar Server 4.4 production Sambar Server 4.3 production Sambar Server 4.3 Sambar Server 4.2.1 production Sambar Server 4.1 production |
| Not Vulnerable: | |
Discussion
Sambar Server Search Script Mixed Query Vulnerability
It has been reported that Sambar Server does not function reliably when it has received some types of queries. This could make it possible for a remote attacker to crash a vulnerable server.
It has been reported that Sambar Server does not function reliably when it has received some types of queries. This could make it possible for a remote attacker to crash a vulnerable server.
Exploit / POC
Sambar Server Search Script Mixed Query Vulnerability
The following proof of concept has been made available:
.+.+a+.+b+.+c+.+d+.+E+.+D+.+gh+sd+.+sF+.+.+G0
An exploit (sambar6_search_results.pm) has been released as part of the MetaSploit Framework 2.0:
The following proof of concept has been made available:
.+.+a+.+b+.+c+.+d+.+E+.+D+.+gh+sd+.+sF+.+.+G0
An exploit (sambar6_search_results.pm) has been released as part of the MetaSploit Framework 2.0:
Solution / Fix
Sambar Server Search Script Mixed Query Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.