Description
iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the preferences tab name field. Attackers can paste a 2,000,000 character buffer into the default diary tab name to trigger an application crash.
Problem types
Improper Validation of Specified Quantity in Input
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/49898 (ExploitDB-49898)
www.splinterware.com/index.html (Vendor Homepage)
www.vulncheck.com/...ories/idailydiary-denial-of-service-poc (VulnCheck Advisory: iDailyDiary 4.30 - Denial of Service (PoC))