CVE-2010-3899

IBM OmniFind Enterprise Edition 8.x and 9.x - Denial of Service via Unlimited Web Crawl Recursion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-3899. PoCs published by Fatih Kilic.

AI-analyzed exploit summary This exploit demonstrates a denial of service vulnerability in a crawler due to lack of recursion depth limit. The provided PHP script generates dynamic links that cause the crawler to enter an endless loop, consuming server resources.

Description

IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.

Exploits (1)

exploitdb WORKING POC
by Fatih Kilic · phpdosmultiple
https://www.exploit-db.com/exploits/15476

This exploit demonstrates a denial of service vulnerability in a crawler due to lack of recursion depth limit. The provided PHP script generates dynamic links that cause the crawler to enter an endless loop, consuming server resources.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Unspecified crawler software (affected by CVE-2010-3899)
No auth needed
Prerequisites: A vulnerable crawler with no recursion depth limit · Ability to host a PHP script accessible to the crawler
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/69078
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15476
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/514688/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44740
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2933

Scores

EPSS 0.0315
EPSS Percentile 86.3%

Details

CWE
CWE-399
Status published
Products (2)
ibm/omnifind 8.0
ibm/omnifind 9.0
Published Nov 12, 2010
Tracked Since Feb 18, 2026