Record summary

CVE-2007-2722 has a selected CVSS score of 7.8; EIP currently links 1 catalogued exploit.

Description

Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBNewzCrawler 1.8 - invalid string Remote Denial of ServiceExploitDB exploitby gbrNot analyzed1 file
ExploitDB

PoC details

References

5