Description
Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Antonio de la Piedra
References
www.exploit-db.com/exploits/47907 (ExploitDB-47907)
www.top-password.com/ (Vendor Homepage)
www.vulncheck.com/...lup-password-recovery-denial-of-service (VulnCheck Advisory: Top Password Software Dialup Password Recovery 1.30 - Denial of Service)