vendor:
GTalk Password Finder
by:
Ismail Tasdelen
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: GTalk Password Finder
Affected Version From: 2.2.1
Affected Version To: 2.2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:nsauditor:gtalk_password_finder:2.2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
GTalk Password Finder 2.2.1 – ‘Key’ Denial of Service (PoC)
GTalk Password Finder 2.2.1 is vulnerable to a denial of service attack when a maliciously crafted input is sent to the 'Key' field. An attacker can exploit this vulnerability by creating a file (poc.txt) with a large number of characters and then copying and pasting the characters in the 'Key' field, which will cause the application to crash.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in the application.