Record summary

CVE-2007-3898 has a selected CVSS score of 6.4; EIP currently links 2 catalogued exploits.

Description

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBMicrosoft Windows Server 2000/2003 - Recursive DNS Spoofing (1)ExploitDB exploitby Alla BerzroutchkoNot analyzed1 file
ExploitDB

PoC details
ExploitDBMicrosoft Windows Server 2000/2003 - Recursive DNS Spoofing (2)ExploitDB exploitby Alla BerzroutchkoNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 16