vendor:
RarmaRadio
by:
Ismael Nava
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: RarmaRadio
Affected Version From: 2.72.8
Affected Version To: 2.75.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:raimersoft:rarmaradio
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64
2021
RarmaRadio 2.72.8 – Denial of Service (PoC)
RarmaRadio 2.72.8 is vulnerable to Denial of Service attack. By creating a new .txt file with a buffer of 100000 'Ñ' characters and pasting the content in the fields Username, Server, Port and User Agent, the application crashes.
Mitigation:
Update to the latest version of RarmaRadio