CVE-2018-25233
MEDIUMWebDrive 18.00.5057 Denial of Service via Secure WebDAV
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25233. PoCs published by Victor Mondragón.
AI-analyzed exploit summary This PoC exploits a denial-of-service vulnerability in WebDrive 18.00.5057 by sending an overly long string (5000 'A' characters) as a username during a connection test, causing the application to crash. The exploit requires manual interaction to paste the payload into the username field.
Description
WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field during Secure WebDAV connection setup. Attackers can input a buffer-overflow payload of 5000 bytes in the username parameter and trigger a connection test to cause the application to crash.
Exploits (1)
This PoC exploits a denial-of-service vulnerability in WebDrive 18.00.5057 by sending an overly long string (5000 'A' characters) as a username during a connection test, causing the application to crash. The exploit requires manual interaction to paste the payload into the username field.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H