Description
SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled exception that crashes the application.
Problem types
Product status
Credits
Sanjana Shetty
References
www.exploit-db.com/exploits/47494 (ExploitDB-47494)
www.nsauditor.com (Official Product Homepage)
www.vulncheck.com/...-of-service-via-registration-name-field (VulnCheck Advisory: SpotAuditor 5.3.1.0 Denial of Service via Registration Name Field)