exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

BSS Continuity CMS 4.2.22640.0 Denial Of Service

BSS Continuity CMS 4.2.22640.0 Denial Of Service
Posted May 21, 2014
Authored by Jerzy Kramarz

BSS Continuity CMS version 4.2.22640.0 suffers from a denial of service vulnerability.

tags | advisory, denial of service
advisories | CVE-2014-3447
SHA-256 | d7e9e0e3d9e9e78fbf9acded3c17d9c2499a49a7fd4828f158617351e69206d1

BSS Continuity CMS 4.2.22640.0 Denial Of Service

Change Mirror Download
Vulnerability title: Remote Denial Of Service in BSS Continuity CMS
CVE: CVE-2014-3447
Vendor: BSS
Product: Continuity CMS
Affected version: 4.2.22640.0
Fixed version: N/A
Reported by: Jerzy Kramarz

Details:

By repeatedly calling node enumeration script, a remote unauthenticated
attacker can overload the underlying database within a few minutes. An
average number of GET requests that would stop the database supporting
the CMS were found to be 70, and in this point the Database daemon have
to be restarted. The vulnerability exists within the system due to heavy
processing invoked by the 'fix paths' script, which attempts to connect
to every node in the system and reiterate its properties via database
update function.


Further details at:
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-3447/


Copyright:
Copyright (c) Portcullis Computer Security Limited 2014, All rights
reserved worldwide. Permission is hereby granted for the electronic
redistribution of this information. It is not to be edited or altered in
any way without the express written consent of Portcullis Computer
Security Limited.

Disclaimer:
The information herein contained may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There
are NO warranties, implied or otherwise, with regard to this information
or its use. Any use of this information is at the user's risk. In no
event shall the author/distributor (Portcullis Computer Security
Limited) be held liable for any damages whatsoever arising out of or in
connection with the use or spread of this information.


Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    57 Files
  • 7
    Jun 7th
    6 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    12 Files
  • 11
    Jun 11th
    27 Files
  • 12
    Jun 12th
    38 Files
  • 13
    Jun 13th
    16 Files
  • 14
    Jun 14th
    14 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    16 Files
  • 18
    Jun 18th
    26 Files
  • 19
    Jun 19th
    15 Files
  • 20
    Jun 20th
    18 Files
  • 21
    Jun 21st
    8 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    19 Files
  • 25
    Jun 25th
    5 Files
  • 26
    Jun 26th
    13 Files
  • 27
    Jun 27th
    42 Files
  • 28
    Jun 28th
    9 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close