vendor:
SpotMSN
by:
Ismail Tasdelen
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SpotMSN
Affected Version From: 2.4.6
Affected Version To: 2.4.6
Patch Exists: NO
Related CWE: N/A
CPE: a:nsauditor:spotmsn:2.4.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
SpotMSN 2.4.6 – ‘Name’ Denial of Service (PoC)
SpotMSN is vulnerable to a denial of service attack when a malicious user sends a large amount of data to the 'Name' field of the 'Register -> Enter Registration Code' window. This causes the application to crash.
Mitigation:
Users should avoid entering large amounts of data into the 'Name' field of the 'Register -> Enter Registration Code' window.