vendor:
Arcadia Internet Store
by:
linux^sex
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Arcadia Internet Store
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:1c:arcadia_internet_store:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows NT/2000
2001
1C: Arcadia Internet Store Denial of Service Vulnerability
1C: Arcadia Internet Store is a online shopping utility for Microsoft Windows NT/2000 that is fully integratable with 1C: Enterprise, another popular Russian web-commerce utility. One of the components of this package, 'tradecli.dll', allows users to specify a template file, the contents of which will be output. Remote attackers can request dos devices, such as 'con', 'com1', 'com2', etc. When 'tradecli.dll' attempts to open these files a denial of service may occur.
Mitigation:
Vendor has not released any patches as of yet