vendor:
SpotAuditor
by:
Rafael Pedrero
7.5
CVSS
HIGH
Denial of Service (DoS) Local Buffer Overflow
119
CWE
Product Name: SpotAuditor
Affected Version From: 3.6.2007
Affected Version To: 3.6.2007
Patch Exists: NO
Related CWE:
CPE: a:nsauditor:spotauditor:3.6.7
Platforms Tested: Windows XP SP3
2019
SpotAuditor v3.6.7 – Denial of Service (PoC)
This exploit allows an attacker to cause a denial of service (DoS) by sending a specially crafted payload to the SpotAuditor software. By copying the content of SpotAuditor_Crash.txt and pasting it into the 'Base64 Encrypted Password' textbox in the 'Base64 Password Decoder' tool, the software crashes.
Mitigation:
Update to a patched version of SpotAuditor software.