vendor:
QVR Client
by:
Luis Martínez
7,5
CVSS
HIGH
Denial of Service (DoS) Local
20
CWE
Product Name: QVR Client
Affected Version From: 5.1
Affected Version To: 5.1
Patch Exists: NO
Related CWE: N/A
CPE: a:qnap:qvr_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10 Pro x64 es
2015
QNap QVR Client 5.1.0.11290 Crash PoC
QNap QVR Client 5.1.0.11290 is vulnerable to a denial of service attack when a maliciously crafted string is sent to the 'Nombre de Usuario' field. This causes the application to crash.
Mitigation:
Ensure that user input is properly validated and sanitized before being used.