vendor:
Foundstone SQLScan
by:
Rafael Pedrero
7.8
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: Foundstone SQLScan
Affected Version From: 1.0.0.0
Affected Version To: 1.0.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:mcafee:foundstone_sqlscan
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3
2018
McAfee Foundstone SQLScan – Denial of Service (PoC) and EIP record overwrite
A denial of service vulnerability exists in McAfee Foundstone SQLScan due to a buffer overflow when copying content from SQLScan_Crash.txt to the 'Hostname/IP' field. An attacker can exploit this vulnerability by running SQLScan, copying the content from SQLScan_Crash.txt to the 'Hostname/IP' field, and clicking the '->' button, resulting in a crash.
Mitigation:
Upgrade to the latest version of McAfee Foundstone SQLScan.