Description
SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64 Encrypted Password field.
Problem types
Product status
Credits
ZwX
References
www.exploit-db.com/exploits/47719 (ExploitDB-47719)
www.nsauditor.com/ (Vendor Homepage)
www.vulncheck.com/...ries/spotauditor-base-denial-of-service (VulnCheck Advisory: SpotAuditor 5.3.2 - 'Base64' Denial Of Service)