Nortel Contivity Denial of Service...

- AV AC AU C I A
发布: 2000-01-18
修订: 2025-04-13

Nortel's recently released Contivity series network devices (extranet switches) shipped with an httpd (to provide an interface for remote administration) which runs on top of VxWorks. A total system crash can occur as a result of exploiting a vulnerability in a cgi-bin program called "cgiproc" that is included with the webserver. If metacharacters such as "!", or "$" are passed to cgiproc, the system will crash (because the characters are not escaped). foo <foo@blacklisted.intranova.net> provided the following example: http://x.x.x.x/manage/cgi/cgiproc?$ [crash] No evidence of this problem being exploited is saved in the logs. Another vulnerability in cgiproc is a lack of authentication when requesting administration webpages. A consequence of this is an attacker being able to view any file on the webserver. foo <foo@blacklisted.intranova.net> also provided an example for this vulnerability: http://x.x.x.x/manage/cgi/cgiproc?Nocfile=/name/and/path/of/file. (interesting places to...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息