vendor:
MSN Password Recovery
by:
Gokkulraj
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: MSN Password Recovery
Affected Version From: 1.30
Affected Version To: 1.30
Patch Exists: NO
Related CWE: N/A
CPE: a:top-password:msn_password_recovery
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64
2020
MSN Password Recovery 1.30 – Denial of Service (PoC)
MSN Password Recovery is vulnerable to a denial of service attack when a maliciously crafted User Name and Registration Code is entered into the application. An attacker can exploit this vulnerability by creating a file containing a large number of 'A' characters, and then pasting the contents of the file into the User Name and Registration Code field. This will cause the application to crash.
Mitigation:
Ensure that input validation is performed on all user-supplied data to prevent maliciously crafted data from causing a denial of service.