vendor:
QtWeb Web Browser
by:
Zer0 Thunder
7,5
CVSS
HIGH
Remote Dos/Crash
20
CWE
Product Name: QtWeb Web Browser
Affected Version From: 3.0
Affected Version To: 3.0
Patch Exists: NO
Related CWE: N/A
CPE: a:qtweb:qtweb_browser
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Sp2, Ubuntu Server
2010
QtWeb 3.0 Remote DoS/Crash Exploit
QtWeb 3.0 Remote DoS/Crash Exploit is a vulnerability that allows an attacker to cause a denial of service (DoS) or crash a remote system by sending a crafted HTML file to the target system. The exploit creates a file named 'zero_qbrwoser.html' which contains a malicious HTML code with a large number of 'A' characters and '42' characters. When the target system opens the file, it will cause a denial of service or crash.
Mitigation:
To mitigate this vulnerability, users should ensure that they are running the latest version of QtWeb and should not open any suspicious HTML files.