vendor:
TimeTables
by:
Ismael Nava
4.3
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: TimeTables
Affected Version From: 2021.6.2
Affected Version To: 2021.6.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64
2020
aSc TimeTables 2021.6.2 – Denial of Service (PoC)
This exploit allows an attacker to cause a denial of service (DoS) by creating a new .txt file with a buffer of 'Z' characters of length 10000 and then copying the content of the file into the Subject title field of the program aSc Timetables 2021.6.2.
Mitigation:
The user should ensure that the Subject title field is not filled with a large amount of characters.