Description
Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Luis Martinez
References
www.exploit-db.com/exploits/50789
www.exploit-db.com/exploits/50789 (ExploitDB-50789)
www.cobiansoft.com/ (Cobian Software Official Homepage)
www.vulncheck.com/...al-denial-of-service-via-password-field (VulnCheck Advisory: Cobian Reflector 0.9.93 RC1 Local Denial of Service via Password Field)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.