CVE-2009-4654
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.8%
from disclosure to weapon0 days
Published on NVDFeb 26
1st PoCNov 17
exploitation probability
6.8%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/10163⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://downloads.securityfocus.com/vulnerabilities/exploits/37042-2.plhttps://exchange.xforce.ibmcloud.com/vulnerabilities/54308http://tcc.hellcode.net/advisories/hellcode-adv005.txthttp://tcc.hellcode.net/sploitz/httpstk.txthttp://www.securityfocus.com/archive/1/507926/100/0/threadedhttp://www.securityfocus.com/bid/37042http://www.securitytracker.com/id?1023188