Description
Foscam Video Management System 1.1.6.6 contains a buffer overflow vulnerability in the UID field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 5000-character buffer into the UID parameter during device addition to trigger an application crash when the Login Check function is invoked.
Problem types
Product status
Credits
Alessandro Magnosi
References
www.exploit-db.com/exploits/47478 (ExploitDB-47478)
www.foscam.com/ (Official Product Homepage)
www.vulncheck.com/...ystem-buffer-overflow-denial-of-service (VulnCheck Advisory: Foscam Video Management System 1.1.6.6 Buffer Overflow Denial of Service)