vendor:
TOWeb V3
by:
BSOD Digital (Fabien DROMAS)
7.5
CVSS
HIGH
Local Format String DOS
CWE
Product Name: TOWeb V3
Affected Version From: TOWeb V3.17
Affected Version To: TOWeb V3.17
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7
2011
TOWeb V3 Local Format String DOS Exploit (TOWeb.MO file corruption)
This exploit allows an attacker to create a corrupt TOWeb.MO file which can lead to a local format string denial of service (DOS) vulnerability. By providing a specially crafted input, the attacker can cause the TOWeb application to crash or become unresponsive.
Mitigation:
The vendor should release a patch or update to fix the vulnerability. Users should update their TOWeb application to the latest version to mitigate the risk.