CVE-2007-2722
NewzCrawler 1.8 - Denial of Service via ENCLOSURE URL Attribute
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2722. PoCs published by gbr.
AI-analyzed exploit summary This exploit demonstrates a remote denial-of-service (DoS) vulnerability in NewzCrawler 1.8 by crafting a malicious RSS 2.0 feed. The vulnerability is triggered when the 'url' attribute of the 'enclosure' element contains invalid strings like '%s', causing the application to crash.
Description
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence.
Exploits (1)
This exploit demonstrates a remote denial-of-service (DoS) vulnerability in NewzCrawler 1.8 by crafting a malicious RSS 2.0 feed. The vulnerability is triggered when the 'url' attribute of the 'enclosure' element contains invalid strings like '%s', causing the application to crash.