Description
SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.
Problem types
Product status
Credits
Velayutham Selvaraj & Praveen Thiyagarayam (TwinTech Solutions)
References
www.exploit-db.com/exploits/47318 (ExploitDB-47318)
www.vulncheck.com/...anger-denial-of-service-buffer-overflow (VulnCheck Advisory: SQL Server Password Changer 1.90 Denial of Service Buffer Overflow)