vendor:
CdBurnerXP
by:
Alan Baeza
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: CdBurnerXP
Affected Version From: 4.5.8.6795
Affected Version To: 4.5.8.6795
Patch Exists: NO
Related CWE: N/A
CPE: a:cdburnerxp:cdburnerxp:4.5.8.6795
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2018
CdBurnerXP 4.5.8.6795 – ‘File Name’ Denial of Service (PoC)
CdBurnerXP 4.5.8.6795 is vulnerable to a denial of service attack when a maliciously crafted file name is pasted into the 'File Name' field. This causes the application to crash.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in the application.