Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2002-0348 PoC — Sun Cobalt RaQ Service.CGI HTTP Server拒绝服务漏洞

Source
Associated Vulnerability
Title:Sun Cobalt RaQ Service.CGI HTTP Server拒绝服务漏洞 (CVE-2002-0348)
Description:Sun Cobalt RaQ是ISPs使用的一种服务方软件。 当远程用户针对service.cgi提交超长URL请求时,导致HTTP Server崩溃: http://10.0.0.1:81/cgi-bin/.cobalt/alert/service.cgi?service=/AAAAAAAAA...(Ax100000)...AAA 管理员必须重启HTTP服务才能恢复正常。
Description
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service
Readme
# CVE-2002-0348
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service

Packetstorm publication at https://packetstormsecurity.com/files/25837/Colbalt-RAQ-v4.txt.html <br>
SecurityFocus publication at https://www.securityfocus.com/bid/4209 <br>

# Author
Alex Hernandez aka <em><a href="https://twitter.com/_alt3kx_" rel="nofollow">(@\_alt3kx\_)</a></em>

# Vendor Reponse: 

The vendor was notified

Posted List^s Security cobalt:<br>
cobalt-security@list.cobalt.com &<br>
jlovell@sun.com<br>
http://www.cobalt.com<br>

# Patch Temporary:
Delete files cgi^s from the system, or disable its possible execution.<br>
File Snapshot

[4.0K] /data/pocs/e038ddc79297c8f8c9ed83ae69b94e2ff299ef23 ├── [1.3K] Cobalt4_DoS.pl ├── [2.7K] CVE-2002-0348.txt ├── [ 34K] LICENSE └── [ 641] README.md 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.